Exposição de Warp

Web servers
30
score de exposição
20
sites usam
1
em exploração
2
críticos
Análise Vexday

Com 30 CVEs catalogadas e uma taxa de exploração ativa 7,4 vezes acima da média geral do catálogo CISA KEV, o Warp apresenta um perfil de risco que merece atenção desproporcional ao seu volume total de vulnerabilidades. A CVE mais perigosa em exploração ativa, CVE-2021-27860, possui EPSS de aproximadamente 0,40 — valor que indica probabilidade relevante de exploração observada em ambiente real. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), o que sugere fragilidades estruturais no controle de acesso que podem facilitar escalonamento de privilégios ou acesso não autorizado a recursos. O surgimento de 10 CVEs nos últimos 90 dias, combinado com 2 falhas de severidade crítica, reforça a necessidade de ciclos ágeis de atualização e monitoramento contínuo para quem depende dessa tecnologia.

CVEs

30 resultados
CVE-2021-27860CRITICALArbitrary file upload vulnerability in FatPipe softwareEPSS 39.8%KEVCVE-2021-27856CRITICALFatPipe software administrative account with no passwordEPSS 5.6%CVE-2021-27858MEDIUMMissing authorization vulnerability in FatPipe softwareEPSS 2.7%CVE-2021-27857HIGHFatPipe software allows unauthenticated configuration downloadEPSS 1.8%CVE-2021-27859HIGHMissing authorization vulnerability in FatPipe softwareEPSS 1.6%CVE-2021-27855HIGHFatPipe software allows privilege escalationEPSS 1.6%CVE-2026-48732HIGHWarp: Remote SSH cwd can lead to unauthorized remote command executionEPSS 1.0%CVE-2026-48719HIGHWarp branch selector command injection via Git branch namesEPSS 0.9%CVE-2023-2754HIGHPlaintext transmission of DNS requests in Windows 1.1.1.1 WARP clientEPSS 0.9%CVE-2022-4428HIGHsupport_uri validation missing in WARP client for WindowsEPSS 0.7%CVE-2026-48731HIGHWarp: Linux external editor command injectionEPSS 0.5%CVE-2026-54699HIGHWarp: OS command injection when opening terminal links from WSLEPSS 0.4%CVE-2022-3512MEDIUMLock WARP switch bypass using warp-cli 'add-trusted-ssid' commandEPSS 0.4%CVE-2022-3320MEDIUMBypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint commandEPSS 0.4%CVE-2022-3321MEDIUMLock WARP switch feature bypass on WARP mobile client for iOSEPSS 0.4%CVE-2022-3337MEDIUMLock WARP switch bypass by removing VPN profile on iOS mobile clientEPSS 0.4%CVE-2025-0651MEDIUMFile symlink abuse might lead to deleting files belonging to SYSTEM userEPSS 0.3%CVE-2022-2145MEDIUMCloudlfare WARP Arbitrary File OverwriteEPSS 0.3%CVE-2023-0652HIGHLocal Privilege Escalation in Cloudflare WARP Installer (Windows)EPSS 0.3%CVE-2026-54686MEDIUMWarp: DCS lifecycle hook spoofing can alter terminal session metadataEPSS 0.3%