VulnSea

gallagher has 5 CVEs on record. 2 were published in the last 90 days. The busiest recent month was March 2026 with 3. The median CVSS is 2.7 (low). None have a confirmed exploitation report. Most affected products: command_centre (3), command_centre_mobile (1), hanwha_vms_integration (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
2.7
Publish → KEV
Last 90 days
2 prev 0

Products

  • command_centre 3
  • command_centre_mobile 1
  • hanwha_vms_integration 1
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

gallagher vulnerabilities

CVEs affecting gallagher, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-27844Low· 2.7
2mo ago

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denia…

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denia…

Sunlitgallagher · command_centreEPSS 0.39%via NVD
CVE-2026-27790Low· 2.7
2mo ago

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * …

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * …

Sunlitgallagher · command_centreEPSS 0.39%via NVD
CVE-2026-20757Low· 2.5
6mo ago

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40…

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40…

Sunlitgallagher · command_centreEPSS 0.07%via NVD
CVE-2026-20801Medium· 5.6
6mo ago

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This …

Sunlitgallagher · hanwha_vms_integrationEPSS 0.10%via NVD
CVE-2025-47147Medium· 5.7
6mo ago

Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a…

Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a…

Sunlitgallagher · command_centre_mobileEPSS 0.07%via NVD
gallagher vulnerabilities (CVEs) · VulnSea