Endpoint security (EDR and XDR)

ESET advisories: every record the registers tie to its products

In one line

37 advisories are attributed to ESET products in this record, covering February 2022 to July 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 8 register entries mention ESET without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

37

tied to a named product

Known exploited

0

in the CISA catalogue

Rated critical

0

by the register

Last checked

Jul 31, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of ESET, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

8 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

37 of the 37 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • CVE-2026-10610highCVSS 8.5Jul 24, 2026

    Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

  • CVE-2026-7483highCVSS 8.5Jul 24, 2026

    Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.

  • WID-SEC-2026-2385lowCVSS 4.4Jul 16, 2026

    Affected products: ESET Server Security

  • CVE-2026-6424mediumCVSS 6.7Jul 16, 2026

    Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system

  • CVE-2026-6423highCVSS 8.5Jul 16, 2026

    A local privilege escalation vulnerability in ESET Inspect Connector.

  • WID-SEC-2026-0926mediumCVSS 4.3Mar 31, 2026

    Affected products: ESET PROTECT

  • CVE-2025-3716mediumCVSS 5.3Mar 30, 2026

    User enumeration in ESET Protect (on-prem) via Response Timing.

  • CVE-2025-13818highCVSS 8.3Feb 06, 2026

    Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent

  • CVE-2025-13176highCVSS 8.4Jan 30, 2026

    Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.

  • WID-SEC-2025-2461mediumCVSS 6.0Nov 03, 2025

    Affected products: ESET NOD32 Antivirus, ESET Endpoint Security, ESET Server Security

  • CVE-2025-4952mediumCVSS 6.8Oct 31, 2025

    Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product's…

  • WID-SEC-2025-1604mediumCVSS 5.0Jul 21, 2025

    Affected products: ESET NOD32 Antivirus, ESET Endpoint Security, ESET Server Security

  • CVE-2025-2425mediumCVSS 5.1Jul 18, 2025

    Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file…

  • WID-SEC-2025-1532mediumCVSS 6.6Jul 11, 2025

    Affected products: ESET NOD32 Antivirus, ESET Endpoint Security

  • CVE-2025-5028mediumCVSS 6.8Jul 11, 2025

    Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so.

  • WID-SEC-2025-0737mediumCVSS 5.8Apr 08, 2025

    Affected products: ESET NOD32 Antivirus, ESET Endpoint Security, ESET Server Security

  • CVE-2024-11859highCVSS 8.4Apr 07, 2025

    DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code.

  • CVE-2024-6654mediumCVSS 6.8Sep 27, 2024

    Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused to disable the protection of the ESET security product and cause…

  • CVE-2024-7400highCVSS 8.5Sep 27, 2024

    The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having…

  • WID-SEC-2024-2196mediumCVSS 7.0Sep 23, 2024

    Affected products: ESET Endpoint Security, ESET NOD32 Antivirus, ESET Server Security

  • WID-SEC-2024-2195mediumCVSS 5.5Sep 23, 2024

    Affected products: ESET Endpoint Security

  • WID-SEC-2024-1621mediumCVSS 6.1Jul 16, 2024

    Affected products: ESET Endpoint Security, ESET NOD32 Antivirus, ESET Server Security

  • WID-SEC-2024-1428mediumCVSS 7.3Jun 21, 2024

    Affected products: ESET NOD32 Antivirus, ESET Endpoint Security, ESET Server Security

  • WID-SEC-2024-0399mediumCVSS 7.8Feb 15, 2024

    Affected products: ESET Endpoint Security, ESET Server Security, ESET NOD32 Antivirus

  • CVE-2024-0353highCVSS 7.8Feb 15, 2024

    Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.

  • CVE-2023-7043lowCVSS 3.3Jan 31, 2024

    Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.

  • WID-SEC-2024-0242lowCVSS 3.3Jan 30, 2024

    Affected products: ESET Endpoint Security, ESET NOD32 Antivirus

  • WID-SEC-2023-3211mediumCVSS 7.5Dec 22, 2023

    Affected products: ESET Server Security, ESET NOD32 Antivirus, ESET Endpoint Security

  • CVE-2023-3160highCVSS 7.8Aug 14, 2023

    The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.

  • WID-SEC-2023-2055highCVSS 7.8Aug 14, 2023

    Affected products: ESET Server Security, ESET NOD32 Antivirus, ESET Endpoint Security

  • WID-SEC-2023-1470mediumCVSS 7.8Jun 15, 2023

    Affected products: ESET Server Security

  • CVE-2023-2847highCVSS 7.8Jun 15, 2023

    During internal security analysis, a local privilege escalation vulnerability has been identified.

  • CVE-2022-2402mediumCVSS 6.5Sep 06, 2022

    The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.

  • CVE-2021-37851highCVSS 7.3May 11, 2022

    Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privileges.

  • CVE-2022-27167highCVSS 7.1May 10, 2022

    Privilege escalation vulnerability in Windows products of ESET, spol.

  • CVE-2022-0615mediumCVSS 5.9Feb 25, 2022

    Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-service condition on the system.

  • CVE-2021-37852highCVSS 7.8Feb 09, 2022

    ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union29Jul 24, 2026
CERT-Bund security advisoriesBSI, Federal Republic of Germany15Jul 16, 2026
Known Exploited Vulnerabilities catalogueCISA, United States1Aug 12, 2025

The entry counts here are the raw register totals for ESET, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does ESET have?

37 advisories in this record are tied by a register to a product of ESET. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any ESET vulnerabilities being actively exploited?

None of the 37 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.

Why does this page show fewer CVEs for ESET than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 8 register entries name ESET without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the ESET advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean ESET is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full ESET record, including sources and open questions

ESET vulnerabilities: all 37 advisories on record, with sources | DecisionOS by nexalign