Product Security Incident Response Team Portal
Nozomi Networks Product Security Incident Response Team (PSIRT) is responsible for investigating security concerns that potentially may affect our products and services.
Read our vulnerability disclosure policy and incident response policy, or report a vulnerability to PSIRT through our secure contact form or by encrypted email using our GPG key.
Security advisories published in 2026
NN-2026:20-01 | 2026-09-08 | Last update: 2026-09-08
Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0
NN-2026:19-01 | 2026-09-08 | Last update: 2026-09-08
Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0
NN-2026:18-01 | 2026-09-08 | Last update: 2026-09-08
Cross-site request forgery in the Guardian/CMC login before 26.3.0
NN-2026:17-01 | 2026-09-08 | Last update: 2026-09-08
Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0
NN-2026:16-01 | 2026-09-08 | Last update: 2026-09-08
Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0
NN-2026:15-01 | 2026-08-11 | Last update: 2026-08-11
Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0
NN-2026:14-01 | 2026-08-11 | Last update: 2026-08-11
Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0
NN-2026:13-01 | 2026-07-07 | Last update: 2026-07-07
Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
NN-2026:12-01 | 2026-07-07 | Last update: 2026-07-07
Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0
NN-2026:11-01 | 2026-07-07 | Last update: 2026-07-07
DoS through oversized audit log entries in Guardian/CMC before 26.2.0
NN-2026:10-01 | 2026-07-07 | Last update: 2026-07-07
Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0
NN-2026:9-01 | 2026-07-07 | Last update: 2026-07-07
Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
NN-2026:8-01 | 2026-07-07 | Last update: 2026-07-07
HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0
NN-2026:7-01 | 2026-05-19 | Last update: 2026-05-19
HTML injection in Smart Polling in Guardian/CMC before 26.1.0
NN-2026:6-01 | 2026-05-19 | Last update: 2026-05-19
HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0
NN-2026:5-01 | 2026-05-19 | Last update: 2026-05-19
HTML injection in Users in Guardian/CMC before 26.1.0
NN-2026:4-01 | 2026-05-19 | Last update: 2026-05-19
HTML injection in Credentials Manager in Guardian/CMC before 26.1.0
NN-2026:3-01 | 2026-05-19 | Last update: 2026-05-19
Angular template injection in Reports in Guardian/CMC before 26.1.0
NN-2026:2-01 | 2026-04-15 | Last update: 2026-04-15
Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0
NN-2026:1-01 | 2026-04-15 | Last update: 2026-04-15
Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0
NN-2025:18-01 | 2026-03-04 | Last update: 2026-03-04
Lack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.0
NN-2025:17-01 | 2026-03-04 | Last update: 2026-03-04
HTML injection in Sensor Map in CMC before 25.6.0
NN-2025:16-01 | 2026-03-04 | Last update: 2026-03-04

