Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · mitel

mitel

· 27 Critical

Total CVEs

135

Critical

27

Products

128

Search All CVEs →

135

Products (128)

micollab48 CVEsmivoice connect23 CVEsmicontact center business11 CVEsconnect onsite7 CVEsmicollab audio\, web \& video conferencing6 CVEsst14.26 CVEsmicloud management portal5 CVEs6869i sip4 CVEs6869i sip firmware4 CVEs6940 sip4 CVEs6930 sip4 CVEsst 14.24 CVEs69403 CVEs6930 sip firmware3 CVEs69203 CVEs69303 CVEs6873i sip3 CVEs6873i sip firmware3 CVEs69053 CVEsmivoice business solution virtual instance3 CVEs69103 CVEsmivoice business express3 CVEscmg suite3 CVEs6970 firmware3 CVEsmivoice office 4003 CVEs69703 CVEs6940 sip firmware3 CVEs6905 sip2 CVEs6865i sip2 CVEs6865i sip firmware2 CVEs6867i sip2 CVEs6867i sip firmware2 CVEs6905 firmware2 CVEs6905 sip firmware2 CVEs6910 firmware2 CVEs6910 sip2 CVEs6910 sip firmware2 CVEs6920 firmware2 CVEs6920 sip2 CVEs6920 sip firmware2 CVEs6930 firmware2 CVEs6940 firmware2 CVEsbusinesscti enterprise2 CVEsmitel 3300 integrated communication platform2 CVEsmivoice business2 CVEsmivoice connect client2 CVEsmivoice mx-one2 CVEsmivoice office 400 smb controller2 CVEsmivoice office 400 smb controller firmware2 CVEsunify openscape xpressions webassistant2 CVEs6873i1 CVEsshoretel conference web1 CVEs6873 firmware1 CVEs68731 CVEs6930w1 CVEs6930w firmware1 CVEs6930w sip1 CVEs6930w sip firmware1 CVEs6869i firmware1 CVEsshoretel firmware1 CVEs6869i1 CVEs6869 firmware1 CVEs6940w1 CVEs6940w firmware1 CVEs6940w sip1 CVEs6940w sip firmware1 CVEs68691 CVEs6867i firmware1 CVEs700d dect1 CVEs700d dect firmware1 CVEsshortel mobility client1 CVEs6867i1 CVEsconnect mobility router1 CVEs6867 firmware1 CVEscx1 CVEsinattend1 CVEsinteraction recording1 CVEs68671 CVEs6865i firmware1 CVEs6865i1 CVEs6865 firmware1 CVEsmicontact center enterprise1 CVEsminet firmware1 CVEssip-dect1 CVEsmitel nupoint messenger1 CVEsmivoic mx-one1 CVEsmivoice1 CVEsmivoice 50001 CVEsmivoice 5330e1 CVEsmivoice 5330e firmware1 CVEsmivoice 69301 CVEsmivoice 6930 firmware1 CVEsmivoice 69401 CVEsmivoice 6940 firmware1 CVEsmivoice border gateway1 CVEssip-dect firmware1 CVEs68651 CVEs6863i sip firmware1 CVEs6863i sip1 CVEsst1 CVEs6863i1 CVEs6863i firmware1 CVEs6863 firmware1 CVEsst firmware1 CVEsopen integration gateway1 CVEsopenscape cp1101 CVEsopenscape cp110 firmware1 CVEsopenscape cp2101 CVEsopenscape cp210 firmware1 CVEsopenscape cp4101 CVEsopenscape cp410 firmware1 CVEsopenscape cp7101 CVEs68631 CVEsopenscape cp710 firmware1 CVEsopenscape cpx101 CVEsopenscape cpx10 firmware1 CVEs69151 CVEs6915 firmware1 CVEs6915 sip1 CVEs6915 sip firmware1 CVEs6873i firmware1 CVEsopenscape dect1 CVEsopenscape dect firmware1 CVEsshoretel1 CVEs6920w1 CVEs6920w firmware1 CVEs6920w sip1 CVEs6920w sip firmware1 CVEs

Recent Vulnerabilities

View all 135
CVE-2025-67823HIGH 8.2

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.

CVE-2025-67822CRITICAL 9.4

A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to gain unauthorized access to user or admin accounts in the system.

CVE-2025-52914HIGH 8.8

A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary SQL database commands.

CVE-2024-55550LOW 2.7KEV

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

CVE-2024-47224MEDIUM 6.5

A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input in URLs. A successful exploit could allow an attacker to perform a phishing attack.

CVE-2024-41714HIGH 8.8

A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) through 1.0.0.27 could allow an authenticated attacker to conduct a command injection attack, due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges within the context of the system.

CVE-2024-41713CRITICAL 9.1KEV

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

CVE-2024-41712MEDIUM 6.6

A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack, due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary commands on the system within the context of the user.

CVE-2024-35315MEDIUM 5.6

A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit could allow an attacker to run arbitrary code with elevated privileges.

CVE-2024-35314CRITICAL 9.8

A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit requires user interaction and could allow an attacker to execute arbitrary scripts.

CVE-2024-35287MEDIUM 6.7

A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges.

CVE-2024-35286CRITICAL 9.8

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

CVE-2024-35285CRITICAL 9.8

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.

CVE-2024-30160MEDIUM 4.8

A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary scripts.

CVE-2024-30159MEDIUM 4.8

A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary scripts.

CVE-2024-30158HIGH 7.2

A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary database and management operations.

CVE-2024-30157HIGH 7.2

A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary database and management operations.

CVE-2024-47912HIGH 8.2

A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform unauthorized data-access attacks due to missing authentication mechanisms. A successful exploit could allow an attacker to access and delete sensitive information.

CVE-2024-47223CRITICAL 9.4

A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access non-sensitive user provisioning information and execute arbitrary SQL database commands.

CVE-2024-47189HIGH 7.7

The API Interface of the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct SQL injection due to insufficient sanitization of user input. A successful exploit could allow an attacker with knowledge of specific details to access non-sensitive user provisioning information and execute arbitrary SQL database commands.

CVE-2024-42514HIGH 8.1

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session.

CVE-2024-36446HIGH 8.8

The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema.

CVE-2024-41710HIGH 7.2KEV

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

CVE-2024-37570HIGH 8.8

On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.

CVE-2024-37569HIGH 8.8

An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoint performs no sanitization on the hostname parameter (sent by an authenticated user), which is subsequently written to disk. During boot, the hostname parameter is executed as part of a series of shell commands. Attackers can achieve remote code execution in the root context by placing shell metacharacters in the hostname parameter.