Product Security Incident Response Team Portal

Nozomi Networks Product Security Incident Response Team (PSIRT) is responsible for investigating security concerns that potentially may affect our products and services.

Read our vulnerability disclosure policy and incident response policy, or report a vulnerability to PSIRT through our secure contact form or by encrypted email using our GPG key.

Security advisories published in 2026

NN-2026:19-01 | 2026-09-08 | Last update: 2026-09-08

Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0

NN-2026:18-01 | 2026-09-08 | Last update: 2026-09-08

Cross-site request forgery in the Guardian/CMC login before 26.3.0

NN-2026:16-01 | 2026-09-08 | Last update: 2026-09-08

Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0

NN-2026:13-01 | 2026-07-07 | Last update: 2026-07-07

Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0

NN-2026:11-01 | 2026-07-07 | Last update: 2026-07-07

DoS through oversized audit log entries in Guardian/CMC before 26.2.0

NN-2026:9-01 | 2026-07-07 | Last update: 2026-07-07

Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0

NN-2026:8-01 | 2026-07-07 | Last update: 2026-07-07

HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0

NN-2026:7-01 | 2026-05-19 | Last update: 2026-05-19

HTML injection in Smart Polling in Guardian/CMC before 26.1.0

NN-2026:6-01 | 2026-05-19 | Last update: 2026-05-19

HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0

NN-2026:5-01 | 2026-05-19 | Last update: 2026-05-19

HTML injection in Users in Guardian/CMC before 26.1.0

NN-2026:4-01 | 2026-05-19 | Last update: 2026-05-19

HTML injection in Credentials Manager in Guardian/CMC before 26.1.0

NN-2026:3-01 | 2026-05-19 | Last update: 2026-05-19

Angular template injection in Reports in Guardian/CMC before 26.1.0

NN-2025:17-01 | 2026-03-04 | Last update: 2026-03-04

HTML injection in Sensor Map in CMC before 25.6.0

NN-2025:16-01 | 2026-03-04 | Last update: 2026-03-04

HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0