Vendor

Symantec vulnerabilities

38 advisories tracked, 1 exploited in the wild according to CISA, 6 published in 2026.

Data refreshed 10 Oct 2026

Patch now

Exploited in the last two years (CISA KEV), or a 10%+ chance of exploitation in the next 30 days (EPSS).

Nothing from Symantec meets this bar right now: no CVE in CISA's exploited list, and none with a high exploitation score.

Products covered

Select a product to see only its advisories.

All tracked advisories

Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.

PublishedCVEProductIssueSeverityEPSSExploited
CVE-2026-11626Endpoint Protection and EDRLocal Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal ToolMEDIUM 5.40.11%–
CVE-2026-3991Data Loss PreventionElevation of Privileges in Symantec Data Loss Prevention Windows EndpointHIGH 7.80.16%–
CVE-2026-3862Identity and access securityCross-Site Scripting Vulnerability in SiteMinder Administrative UIMEDIUM 4.60.25%–
CVE-2025-13919Endpoint Protection and EDRComponent Object Model (COM) Hijacking in Symantec Endpoint Protection Windows ClientMEDIUM 4.40.15%–
CVE-2025-13918Endpoint Protection and EDRElevation of Privileges in Symantec Endpoint Protection Windows ClientMEDIUM 6.70.17%–
CVE-2025-13917ProxySG and Edge SWGElevation of Privileges in Web Security Services (WSS) AgentHIGH 70.10%–
CVE-2025-8661Identity and access securityStored Cross-Site Scripting in Symantec PGP Encryption 11.0.1MEDIUM 4.60.19%–
CVE-2025-8660Identity and access securityPrivilege Escalation in Symantec PGP Encryption 11.0.1MEDIUM 5.60.30%–
CVE-2025-24507Identity and access securityThis vulnerability allows appliance compromise at boot time.HIGH 8.90.18%–
CVE-2025-24506Identity and access securityA specific authentication strategy allows to learn ids of PAM users associated with certain authentication…MEDIUM 5.30.24%–
CVE-2025-24505Identity and access securityThis vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on t…HIGH 8.80.29%–
CVE-2025-24504Identity and access securityAn improper input validation the CSRF filter results in unsanitized user input written to the application l…MEDIUM 5.30.23%–
CVE-2025-24503Identity and access securityA malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted li…CRITICAL 9.30.24%–
CVE-2025-24502Identity and access securityAn improper session validation allows an unauthenticated attacker to cause certain request notifications to…MEDIUM 5.30.22%–
CVE-2025-24501Identity and access securityAn improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially cr…MEDIUM 5.30.29%–
CVE-2025-24500Identity and access securityThe vulnerability allows an unauthenticated attacker to access information in PAM database.HIGH 8.70.23%–
CVE-2024-38496Identity and access securitySymantec Privileged Access Manager Insecure Direct Object Reference vulnerabilityMEDIUM 5.10.25%–
CVE-2024-38495Identity and access securitySymantec Privileged Access Manager User Enumeration vulnerabilityMEDIUM 5.30.28%–
CVE-2024-38494Identity and access securitySymantec Privileged Access Manager Remote Command Execution vulnerabilityHIGH 8.60.61%–
CVE-2024-38493Identity and access securitySymantec Privileged Access Manager Reflected Cross Site Scripting vulnerabilityMEDIUM 6.80.30%–
CVE-2024-38492Identity and access securitySymantec Privileged Access Manager Remote Command Execution vulnerabilityCRITICAL 9.40.94%–
CVE-2024-38491Identity and access securitySymantec Privileged Access Manager SQL Injection vulnerabilityHIGH 8.40.28%–
CVE-2024-36458Identity and access securitySymantec Privileged Access Manager Privilege Escalation vulnerabilityMEDIUM 5.10.20%–
CVE-2024-36457Identity and access securitySymantec Privileged Access Manager Authentication Bypass vulnerabilityMEDIUM 5.30.29%–
CVE-2024-36456Identity and access securitySymantec Privileged Access Manager Remote Command Execution vulnerabilityCRITICAL 9.40.94%–
CVE-2024-36455Identity and access securitySymantec Privileged Access Manager Remote Command Execution vulnerabilityCRITICAL 9.40.47%–
CVE-2024-36459Identity and access securityCross-Site Scripting Vulnerability in Symantec SiteMinder Web AgentHIGH 8.40.42%–
CVE-2023-23957Identity and access securityOpen Redirection Vulnerability in Symantec Identity Portal 14.4–0.32%–
CVE-2023-23952ProxySG and Edge SWGAdvanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection in Advanced Secure Gateway, Content AnalysisCRITICAL 9.81.3%–
CVE-2023-23953ProxySG and Edge SWGAdvanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevati…HIGH 7.80.19%–
CVE-2023-23954ProxySG and Edge SWGAdvanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored C…MEDIUM 5.40.34%–
CVE-2023-23955ProxySG and Edge SWGAdvanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-S…HIGH 8.10.47%–
CVE-2023-23956Identity and access securityA user can supply malicious HTML and JavaScript code that will be executed in the client browserMEDIUM 6.13.1%–
CVE-2023-23949Identity and access securityAn authenticated user can supply malicious HTML and JavaScript code that will be executed in the client bro…HIGH 8.10.56%–
CVE-2023-23950Identity and access securityUser’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.MEDIUM 6.10.51%–
CVE-2023-23951Identity and access securityAbility to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the app…MEDIUM 6.10.51%–
CVE-2022-25631Endpoint Protection and EDRSymantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege in Symantec Endpoint ProtectionHIGH 7.80.17%–
CVE-2017-6327Messaging GatewayMessaging Gateway Remote Code ExecutionHIGH 8.836%Yes

Sources: Symantec security advisories, CISA KEV and FIRST EPSS. Severity is the vendor's own rating.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.