Email security

Proofpoint advisories: every record the registers tie to its products

In one line

23 advisories are attributed to Proofpoint products in this record, covering December 2022 to November 2025, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 6 register entries mention Proofpoint without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

23

tied to a named product

Known exploited

0

in the CISA catalogue

Rated critical

2

by the register

Last checked

Jul 18, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Proofpoint, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

6 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

23 of the 23 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • WID-SEC-2025-2484mediumCVSS 5.4Nov 04, 2025

    Affected products: Proofpoint Insider Threat Management

  • CVE-2025-8558lowCVSS 2.3Nov 03, 2025

    Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent…

  • CVE-2024-10635mediumCVSS 6.1Apr 28, 2025

    Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy…

  • CVE-2025-0431mediumCVSS 5.8Mar 19, 2025

    Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of…

  • CVE-2023-5770mediumCVSS 5.3Jan 09, 2024

    Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body of a…

  • WID-SEC-2023-2339highCVSS 8.8Sep 15, 2023

    Affected products: Proofpoint Insider Threat Management

  • CVE-2023-4828mediumCVSS 6.4Sep 13, 2023

    An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the server's configuration of any already-registered…

  • CVE-2023-4803mediumCVSS 4.8Sep 13, 2023

    A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator…

  • CVE-2023-4802mediumCVSS 4.8Sep 13, 2023

    A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated…

  • CVE-2023-4801highCVSS 7.5Sep 13, 2023

    An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a…

  • WID-SEC-2023-1589mediumCVSS 5.5Jun 29, 2023

    Affected products: Proofpoint Insider Threat Management

  • WID-SEC-2023-1587mediumCVSS 6.5Jun 29, 2023

    Affected products: Proofpoint Insider Threat Management

  • CVE-2023-36002mediumCVSS 4.3Jun 27, 2023

    A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS…

  • CVE-2023-36000mediumCVSS 6.5Jun 27, 2023

    A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive…

  • CVE-2023-35998mediumCVSS 4.6Jun 27, 2023

    A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects.

  • CVE-2023-2818mediumCVSS 5.5Jun 27, 2023

    An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring.

  • CVE-2023-2820mediumCVSS 6.1Jun 14, 2023

    An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to…

  • CVE-2023-2819mediumCVSS 4.3Jun 14, 2023

    A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (PTR/TRAP) could allow an authenticated administrator on an adjacent…

  • CVE-2023-0090criticalCVSS 9.8Mar 08, 2023

    The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'.

  • CVE-2023-0089highCVSS 8.8Mar 08, 2023

    The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'.

  • CVE-2022-46334highCVSS 7.8Dec 21, 2022

    Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions.

  • CVE-2022-46333highCVSS 7.2Dec 06, 2022

    The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope.

  • CVE-2022-46332criticalCVSS 9.6Dec 06, 2022

    The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin…

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union25Nov 03, 2025
CERT-Bund security advisoriesBSI, Federal Republic of Germany4Nov 04, 2025

The entry counts here are the raw register totals for Proofpoint, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Proofpoint have?

23 advisories in this record are tied by a register to a product of Proofpoint. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Proofpoint vulnerabilities being actively exploited?

None of the 23 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.

Why does this page show fewer CVEs for Proofpoint than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 6 register entries name Proofpoint without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Proofpoint advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Proofpoint is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Proofpoint record, including sources and open questions

Proofpoint vulnerabilities: all 23 advisories on record, with sources | DecisionOS by nexalign