VulnSea

UTMStack has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 7. The median CVSS is 7.7 (high), with 2 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
7.7
Publish → KEV
—
Last 90 days
7 prev 0

Products

  • UTMStack 7
7
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

UTMStack vulnerabilities

CVEs affecting UTMStack, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-82045Medium· 6.5
yesterday

UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query with String.format() …

UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query with String.format() …

▾ SunlitUTMStack · UTMStackvia NVD
CVE-2026-82044High· 7.7
yesterday

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.download…

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.download…

▾ TwilightUTMStack · UTMStackvia NVD
CVE-2026-82043Medium· 5.3
yesterday

UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endp…

UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endp…

▾ SunlitUTMStack · UTMStackvia NVD
CVE-2026-82042Critical· 9.8
yesterday

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable valu…

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable valu…

▾ MidnightUTMStack · UTMStackvia NVD
CVE-2026-82041Critical· 9.9
yesterday

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied …

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied …

▾ MidnightUTMStack · UTMStackvia NVD
CVE-2026-82040Medium· 5.0
yesterday

UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticated attackers to make the server send requests to arbitrary internal or cloud metadata ho…

UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticated attackers to make the server send requests to arbitrary internal or cloud metadata ho…

▾ SunlitUTMStack · UTMStackvia NVD
CVE-2026-82039High· 8.8
yesterday

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are insert…

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are insert…

▾ TwilightUTMStack · UTMStackvia NVD
UTMStack vulnerabilities (CVEs) · VulnSea