Arc Nozominetworks Arc

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Nozominetworks Arc.

By the Year

In 2026 there have been 3 vulnerabilities in Nozominetworks Arc with an average score of 6.0 out of ten.

Year Vulnerabilities Average Score
2026 3 6.03

It may take a day or so for new Arc vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Nozominetworks Arc Security Vulnerabilities

Nozomi Edge Path Traversal in Offline Archives Deletes Files
CVE-2026-33922 6.8 - Medium - August 11, 2026

A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing traversal sequences and delete arbitrary files reachable by the Arc process, which runs with administrative privileges on the host.

Directory traversal

Windows Install of Npcap Leaves Driver Insecurely Accessible
CVE-2026-33921 4.8 - Medium - August 11, 2026

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capture the traffic reaching the host, which discloses information belonging both to the host and to other systems on the same network segment, and to send arbitrary raw packets on that segment.

Insecure Default Initialization of Resource

Nozomi Arc Agent TLS Cert Validation Flaw Enabling MITM
CVE-2025-40896 6.5 - Medium - March 04, 2026

The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Arc agent and the Guardian or CMC. This could result in theft of the client token and sensitive information (such as assets and alerts), impersonation of the server, or injection of spoofed data (such as false asset information or vulnerabilities) into the Guardian or CMC.

Improper Certificate Validation

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Nozominetworks Arc or by Nozominetworks? Click the Watch button to subscribe.

subscribe