{"record":"Akamai evidence record","url":"https://nexalign.io/vendors/akamai","vendor":{"slug":"akamai","name":"Akamai","domain":"akamai.com","category":"network","categoryLabel":"Network security"},"lastChecked":"2026-07-18T04:17:58.939Z","coverage":{"earliest":"2007-04-18T02:20:00.000Z","latest":"2026-07-03T16:21:51.669Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":48,"kindsOfSource":4,"attributedAdvisories":9,"knownExploited":0,"registerEntriesNotAttributable":15,"practitionerThreads":11,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":24,"latest":"2026-05-08T00:00:00.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":9,"latest":"2026-05-08T16:16:10.510Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":11,"latest":"2026-03-07T20:24:23.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":4,"latest":"2026-07-03T16:21:51.669Z"}],"advisories":{"shown":6,"total":9,"truncated":true,"items":[{"id":"CVE-2026-34354","description":"Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation.","severity":"high","cvss":7.4,"knownExploited":false,"date":"2026-05-08T16:16:10.510Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-34354","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28788"]},{"id":"CVE-2026-26365","description":"Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header \"Connection…","severity":"medium","cvss":4,"knownExploited":false,"date":"2026-02-23T09:17:01.210Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-26365","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7487"]},{"id":"CVE-2025-66373","description":"Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling.","severity":"medium","cvss":4.8,"knownExploited":false,"date":"2025-12-04T17:15:56.867Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-66373","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-201241"]},{"id":"CVE-2025-53841","description":"The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation…","severity":"high","cvss":7.8,"knownExploited":false,"date":"2025-12-03T15:15:51.830Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-53841","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-200974"]},{"id":"CVE-2025-54142","description":"Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection…","severity":"medium","cvss":4,"knownExploited":false,"date":"2025-08-29T01:15:35.250Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-54142","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26158"]},{"id":"CVE-2025-32094","description":"An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26.","severity":"medium","cvss":4,"knownExploited":false,"date":"2025-08-07T05:15:45.667Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-32094","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23911"]}]},"practitionerThreads":{"shown":5,"total":11,"truncated":true,"items":[{"title":"Improving Antibot Biometric Protections: A Harsh Lesson from Akamai (2024)","context":"Hacker News","url":"https://news.ycombinator.com/item?id=47291135","date":"2026-03-07T20:24:23.000Z"},{"title":"Fermyon Joins Akamai","context":"Hacker News","url":"https://news.ycombinator.com/item?id=46107946","date":"2025-12-01T14:38:57.000Z"},{"title":"Linode / Akamai US-EAST is down","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44700252","date":"2025-07-27T10:27:05.000Z"},{"title":"XML External Entity (XXE) Injection in Akamai CloudTest","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44426517","date":"2025-06-30T18:43:10.000Z"},{"title":"Akamai, Microsoft Disagree on Severity of Unpatched 'BadSuccessor' Flaw","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44066429","date":"2025-05-22T20:19:50.000Z"}]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Akamai Reviews, Competitors and Pricing","host":"peerspot.com","url":"https://www.peerspot.com/products/akamai-reviews","date":null},{"title":"Akamai Technologies - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Akamai_Technologies","date":null},{"title":"Akamai Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/cloud-web-application-and-api-protection/vendor/akamai","date":null},{"title":"Akamai Guardicore Segmentation Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/akamai-guardicore-segmentation","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 15 register entries mention Akamai without naming a product of Akamai as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}