{"record":"Bitdefender evidence record","url":"https://nexalign.io/vendors/bitdefender","vendor":{"slug":"bitdefender","name":"Bitdefender","domain":"bitdefender.com","category":"endpoint-security","categoryLabel":"Endpoint security (EDR and XDR)"},"lastChecked":"2026-07-17T10:17:25.652Z","coverage":{"earliest":"2007-11-01T16:04:00.000Z","latest":"2026-07-15T10:41:41.328Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":41,"kindsOfSource":4,"attributedAdvisories":33,"knownExploited":0,"registerEntriesNotAttributable":2,"practitionerThreads":0,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":28,"latest":"2026-07-14T07:11:50.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":7,"latest":"2026-07-15T10:41:41.328Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":4,"latest":"2026-07-03T04:17:19.096Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":2,"latest":"2026-05-11T18:05:44.000Z"}],"advisories":{"shown":6,"total":33,"truncated":true,"fullList":"https://nexalign.io/vendors/bitdefender/advisories","items":[{"id":"WID-SEC-2026-2361","description":"Affected products: Bitdefender Total Security, Bitdefender Internet Security","severity":"medium","cvss":7.3,"knownExploited":false,"date":"2026-07-15T10:41:41.328Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2361"]},{"id":"CVE-2026-6851","description":"An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a…","severity":"high","cvss":7,"knownExploited":false,"date":"2026-07-14T07:11:50.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43632"]},{"id":"CVE-2026-10047","description":"The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kernel/handler.c.","severity":"high","cvss":8.5,"knownExploited":false,"date":"2026-06-02T14:17:15.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33944"]},{"id":"CVE-2026-10046","description":"Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in napoca/guests/bios_handlers.c.","severity":"high","cvss":8.5,"knownExploited":false,"date":"2026-06-02T14:16:21.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33943"]},{"id":"WID-SEC-2025-2810","description":"Affected products: Bitdefender Antivirus, Bitdefender Total Security, Bitdefender Internet Security","severity":"medium","cvss":7.8,"knownExploited":false,"date":"2025-12-11T09:45:28.814Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2810"]},{"id":"CVE-2025-7073","description":"A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges.","severity":"high","cvss":8.8,"knownExploited":false,"date":"2025-12-10T09:46:40.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-202416"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Bitdefender Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/bitdefender","date":null},{"title":"Bitdefender - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Bitdefender","date":null},{"title":"Bitdefender Total Security Review: A Feature-Loaded Security Suite That Protects All Your Devices | PCMag","host":"pcmag.com","url":"https://www.pcmag.com/reviews/bitdefender-total-security","date":null},{"title":"Bitdefender Managed Detection and Response Services Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/bitdefender-managed-detection-and-response-services","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 2 register entries mention Bitdefender without naming a product of Bitdefender as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming Bitdefender was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}