payara has 2 CVEs on record. 1 was published in the last 90 days. The median CVSS is 6.3 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 1
Products
- fish.payara.distributions:payara 1
- org.glassfish.admingui.common.security 1
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
payara vulnerabilities
CVEs affecting payara, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-92082Medium· 6.3By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration de…
▾ SunlitPayara · org.glassfish.admingui.common.securityEPSS 0.30%via NVD
CVE-2026-12986HighPayara Server Full has a Cross-Site Request Forgery vulnerability
Payara Server Full has a Cross-Site Request Forgery vulnerability
▾ Twilightpayara · fish.payara.distributions:payaraEPSS 0.27%via GHSA