{"record":"Proofpoint evidence record","url":"https://nexalign.io/vendors/proofpoint","vendor":{"slug":"proofpoint","name":"Proofpoint","domain":"proofpoint.com","category":"email-security","categoryLabel":"Email security"},"lastChecked":"2026-07-18T04:19:23.914Z","coverage":{"earliest":"2011-05-05T14:00:00.000Z","latest":"2026-07-18T04:19:23.914Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":37,"kindsOfSource":5,"attributedAdvisories":23,"knownExploited":0,"registerEntriesNotAttributable":6,"practitionerThreads":3,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":25,"latest":"2025-11-03T18:40:03.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":4,"latest":"2025-11-04T12:13:23.585Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":4,"latest":"2026-07-18T04:19:23.914Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":3,"latest":"2024-11-01T20:14:39.000Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":1,"latest":"2025-12-20T18:32:28.000Z"}],"advisories":{"shown":6,"total":23,"truncated":true,"fullList":"https://nexalign.io/vendors/proofpoint/advisories","items":[{"id":"WID-SEC-2025-2484","description":"Affected products: Proofpoint Insider Threat Management","severity":"medium","cvss":5.4,"knownExploited":false,"date":"2025-11-04T12:13:23.585Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2484"]},{"id":"CVE-2025-8558","description":"Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent…","severity":"low","cvss":2.3,"knownExploited":false,"date":"2025-11-03T18:40:03.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-37519"]},{"id":"CVE-2024-10635","description":"Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy…","severity":"medium","cvss":6.1,"knownExploited":false,"date":"2025-04-28T20:36:43.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-54529"]},{"id":"CVE-2025-0431","description":"Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of…","severity":"medium","cvss":5.8,"knownExploited":false,"date":"2025-03-19T16:18:23.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-6734"]},{"id":"CVE-2023-5770","description":"Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body of a…","severity":"medium","cvss":5.3,"knownExploited":false,"date":"2024-01-09T22:02:03.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58053"]},{"id":"WID-SEC-2023-2339","description":"Affected products: Proofpoint Insider Threat Management","severity":"high","cvss":8.8,"knownExploited":false,"date":"2023-09-15T09:56:28.652Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2339"]}]},"practitionerThreads":{"shown":3,"total":3,"truncated":false,"items":[{"title":"Ask HN: Proofpoint is blocking our emails. Any recourse?","context":"Hacker News","url":"https://news.ycombinator.com/item?id=42021072","date":"2024-11-01T20:14:39.000Z"},{"title":"Phishing Campaign Exploits Proofpoint to Send Spoofed Emails","context":"Hacker News","url":"https://news.ycombinator.com/item?id=41106257","date":"2024-07-30T05:26:57.000Z"},{"title":"Spam blocklist SORBS closed by its owner, Proofpoint","context":"Hacker News","url":"https://news.ycombinator.com/item?id=40624439","date":"2024-06-09T13:52:08.000Z"}]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Proofpoint Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/proofpoint-1145193703","date":null},{"title":"Proofpoint Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/email-security/vendor/proofpoint","date":null},{"title":"Proofpoint - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Proofpoint","date":null},{"title":"Proofpoint ET Intelligence reviews 2026","host":"peerspot.com","url":"https://www.peerspot.com/products/proofpoint-et-intelligence-reviews","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 6 register entries mention Proofpoint without naming a product of Proofpoint as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}