VulnSea

pexip has 14 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 10 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 10. The median CVSS is 7.6 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-617 (6). Most affected products: Infinity (10), pexip_infinity (4).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
7.6
Publish → KEV
—
Last 90 days
10 prev 0

Products

  • Infinity 10
  • pexip_infinity 4
14
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

pexip vulnerabilities

CVEs affecting pexip, newest first. Open any entry for full detail, references, and exploit status.

14 CVEsRSS

CVE-2026-103110Critical· 9.8
yesterday

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.

▾ MidnightPexip · InfinityEPSS 0.61%via NVD
CVE-2026-103109High· 7.7
yesterday

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A…

▾ TwilightPexip · InfinityEPSS 0.24%via NVD
CVE-2026-103108High· 7.5
yesterday

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service

▾ TwilightPexip · InfinityEPSS 0.31%via NVD
CVE-2026-103106High· 7.8
yesterday

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an …

▾ TwilightPexip · InfinityEPSS 0.14%via NVD
CVE-2026-103105High· 8.8
yesterday

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as…

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as…

▾ TwilightPexip · InfinityEPSS 0.18%via NVD
CVE-2026-103100High· 7.5
yesterday

Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.

Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.

▾ TwilightPexip · InfinityEPSS 0.26%via NVD
CVE-2026-103101High· 8.6
yesterday

Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.

Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.

▾ TwilightPexip · InfinityEPSS 0.27%via NVD
CVE-2026-103099High· 7.5
yesterday

Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.

Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.

▾ TwilightPexip · InfinityEPSS 0.31%via NVD
CVE-2026-103104High· 7.5
yesterday

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.

▾ TwilightPexip · InfinityEPSS 0.31%via NVD
CVE-2026-103102High· 8.6
yesterday

Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service

Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessin…

▾ TwilightPexip · InfinityEPSS 0.32%via NVD
CVE-2025-66379High· 7.5
9mo ago

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

▾ Twilightpexip · pexip_infinityEPSS 0.37%via NVD
CVE-2025-66377High· 7.5
9mo ago

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operati…

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operati…

▾ Twilightpexip · pexip_infinityEPSS 0.21%via NVD
CVE-2025-59683High· 8.2
9mo ago

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and…

▾ Twilightpexip · pexip_infinityEPSS 0.33%via NVD
CVE-2025-49088Medium· 5.9
9mo ago

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a craf…

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a craf…

▾ Sunlitpexip · pexip_infinityEPSS 0.32%via NVD
pexip vulnerabilities (CVEs) · VulnSea