{"record":"CyberArk evidence record","url":"https://nexalign.io/vendors/cyberark","vendor":{"slug":"cyberark","name":"CyberArk","domain":"cyberark.com","category":"pam","categoryLabel":"Privileged access management"},"lastChecked":"2026-07-27T16:17:38.220Z","coverage":{"earliest":"2018-04-12T15:00:00.000Z","latest":"2026-07-27T16:17:38.220Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":48,"kindsOfSource":4,"attributedAdvisories":2,"knownExploited":0,"registerEntriesNotAttributable":33,"practitionerThreads":4,"independentItems":6,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":35,"latest":"2026-06-12T04:32:03.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":2,"latest":"2025-11-27T03:15:58.613Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":7,"latest":"2026-07-27T16:17:38.220Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":4,"latest":"2025-08-07T06:25:35.000Z"}],"advisories":{"shown":2,"total":2,"truncated":false,"items":[{"id":"CVE-2025-13762","description":"Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue…","severity":"medium","cvss":4.8,"knownExploited":false,"date":"2025-11-27T03:15:58.613Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-13762","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199782"]},{"id":"CVE-2025-49831","description":"An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a…","severity":"critical","cvss":9.8,"knownExploited":false,"date":"2025-07-15T21:15:31.783Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-49831","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21563"]}]},"practitionerThreads":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44821250","date":"2025-08-07T06:25:35.000Z"},{"title":"Palo Alto Networks agrees to buy CyberArk for $25B","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44739041","date":"2025-07-30T20:19:44.000Z"},{"title":"Palo Alto Networks Announces Agreement to Acquire CyberArk","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44734455","date":"2025-07-30T14:10:03.000Z"},{"title":"Palo Alto Networks closing on over $20B acquisition of CyberArk","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44727871","date":"2025-07-29T20:26:00.000Z"}]},"independentCoverage":{"shown":5,"total":6,"truncated":true,"items":[{"title":"CyberArk Secrets Management Reviews, Competitors and Pricing","host":"peerspot.com","url":"https://www.peerspot.com/products/cyberark-secrets-management-reviews","date":null},{"title":"CyberArk - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/CyberArk","date":null},{"title":"CyberArk Products and Reviews","host":"peerspot.com","url":"https://www.peerspot.com/vendors/cyberark","date":null},{"title":"CyberArk Privileged Access Manager: Pros and Cons 2026","host":"peerspot.com","url":"https://www.peerspot.com/products/cyberark-privileged-access-manager-pros-and-cons","date":null},{"title":"CyberArk Reviews, Ratings & Features 2025 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/access-management/vendor/cyberark","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 33 register entries mention CyberArk without naming a product of CyberArk as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}