Endpoint security (EDR and XDR)

Bitdefender advisories: every record the registers tie to its products

In one line

33 advisories are attributed to Bitdefender products in this record, covering January 2020 to July 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 2 register entries mention Bitdefender without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

33

tied to a named product

Known exploited

0

in the CISA catalogue

Rated critical

4

by the register

Last checked

Jul 17, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Bitdefender, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

2 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

33 of the 33 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • WID-SEC-2026-2361mediumCVSS 7.3Jul 15, 2026

    Affected products: Bitdefender Total Security, Bitdefender Internet Security

  • CVE-2026-6851highCVSS 7.0Jul 14, 2026

    An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a…

  • CVE-2026-10047highCVSS 8.5Jun 02, 2026

    The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kernel/handler.c.

  • CVE-2026-10046highCVSS 8.5Jun 02, 2026

    Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in napoca/guests/bios_handlers.c.

  • WID-SEC-2025-2810mediumCVSS 7.8Dec 11, 2025

    Affected products: Bitdefender Antivirus, Bitdefender Total Security, Bitdefender Internet Security

  • CVE-2025-7073highCVSS 8.8Dec 10, 2025

    A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges.

  • CVE-2025-5317mediumCVSS 6.8Nov 11, 2025

    An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass the…

  • CVE-2025-1987criticalCVSS 9.3Jun 21, 2025

    A Cross-Site Scripting (XSS) vulnerability has been identified in Psono-Client’s handling of vault entries of type website_password and bookmark, as used in Bitdefender SecurePass.

  • CVE-2025-2245mediumCVSS 6.9Apr 04, 2025

    A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode.

  • CVE-2025-2243mediumCVSS 6.9Apr 04, 2025

    A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leading characters in DNS requests.

  • CVE-2025-2244criticalCVSS 9.5Apr 04, 2025

    A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation.

  • CVE-2024-13870lowCVSS 1.8Mar 12, 2025

    An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an…

  • CVE-2024-13871criticalCVSS 9.4Mar 12, 2025

    A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490).

  • CVE-2024-13872criticalCVSS 9.4Mar 12, 2025

    Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the…

  • CVE-2020-8094highCVSS 8.8Jan 15, 2025

    An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL…

  • CVE-2024-11128highCVSS 8.4Jan 13, 2025

    A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injection) without being blocked by…

  • WID-SEC-2024-0775mediumCVSS 7.8Nov 28, 2024

    Affected products: Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus

  • WID-SEC-2024-3235highCVSS 8.5Oct 18, 2024

    Affected products: Bitdefender Total Security

  • CVE-2023-49570highCVSS 8.6Oct 18, 2024

    A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an entity that isn't authorized to issue…

  • CVE-2023-49567highCVSS 8.6Oct 18, 2024

    A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's certificate, which allows an attacker to…

  • CVE-2023-6058highCVSS 8.6Oct 18, 2024

    A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections.

  • CVE-2023-6057highCVSS 8.6Oct 18, 2024

    A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of certificates issued using the DSA signature algorithm.

  • CVE-2023-6056highCVSS 8.6Oct 18, 2024

    A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates.

  • CVE-2023-6055highCVSS 8.6Oct 18, 2024

    A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails to properly validate website certificates.

  • WID-SEC-2023-1756highCVSS 8.1Jul 17, 2023

    Affected products: Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus

  • CVE-2023-3633highCVSS 8.1Jul 14, 2023

    An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash.

  • WID-SEC-2023-1296mediumCVSS 6.7May 24, 2023

    Affected products: Bitdefender Antivirus, Bitdefender Internet Security, Bitdefender Total Security

  • CVE-2022-0357mediumCVSS 6.7May 24, 2023

    Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an…

  • WID-SEC-2022-1921highCVSS 8.6Nov 01, 2022

    Affected products: Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus

  • CVE-2022-3369highCVSS 8.6Nov 01, 2022

    An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows, allows an attacker to delete privileged registry keys by pointing a…

  • CVE-2020-15279mediumCVSS 4.0May 18, 2021

    An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning…

  • CVE-2020-15293mediumCVSS 6.1Dec 17, 2020

    Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input validation may lead to denial of service…

  • CVE-2019-17102highCVSS 8.3Jan 27, 2020

    An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91.

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union28Jul 14, 2026
CERT-Bund security advisoriesBSI, Federal Republic of Germany7Jul 15, 2026

The entry counts here are the raw register totals for Bitdefender, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Bitdefender have?

33 advisories in this record are tied by a register to a product of Bitdefender. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Bitdefender vulnerabilities being actively exploited?

None of the 33 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.

Why does this page show fewer CVEs for Bitdefender than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 2 register entries name Bitdefender without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Bitdefender advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Bitdefender is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Bitdefender record, including sources and open questions

Bitdefender vulnerabilities: all 33 advisories on record, with sources | DecisionOS by nexalign