Vendor scorecard
CyberArk
CyberArk security disclosure record — CVE volume, CVSS severity mix and product-category breakdown, sourced from the NIST NVD.
CPE: cyberark
Product families
2
Open in latest
6
Inferred — see methodology
Last disclosure
Feb 25, 2026
01
Product categories
2 trackedCVE volume, severity mix and the inferred latest shipping version per category.
| Category | CVEs | Volume | Severity mix | Open | Inferred latest |
|---|---|---|---|---|---|
| Conjur / Endpoint Privilege ManagerIdentity & Access Managementconjur, endpoint_privilege_manager | 2 | 6 | 25.11.0MED | ||
| Privileged Access (Vault/PSM)Identity & Access Managementprivileged_access_security, password_vault, privileged_session_manager | 0 | 0 | 10.1MED |
02
Recent CVEs
2 shownMost recently published, newest first. Each ID links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-2914(opens NVD record) | High | 7.8 | CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs | Feb 25, 2026 |
| CVE-2025-66374(opens NVD record) | High | 7.8 | CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task. | Feb 3, 2026 |
2 CVEs · 2 product families