LIVE · cybersecurity feed
Live wire
vendor

Bitwarden

4 CVEs published in the last four months. Exploited flaws first.

Critical0
High4
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-601048.7highserverBitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belong59d ago
CVE-2026-436408.1highserverBitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating117d ago
CVE-2026-436398highserverBitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service 117d ago
CVE-2026-575207.1highserverBitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom us72d ago

Filter the full tracker by Bitwarden