Vendor
Netflix vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 17 vulnerabilities in Netflix: 0 in the last 7 days and 13 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-71417, was published on 18 August 2026.
- Last 7 days
- 0
- Last 90 days
- 13
- Critical, all time
- 2
- Exploited in the wild
- 0
About Netflix
Netflix is an entertainment company that provides streaming media services including films, television series, and documentaries.
Latest Netflix vulnerabilities
- CVE-2026-71417: Netflix Lemur arbitrary certificate revocation via duplicate uploadhighCVSS 7.3EPSS 0.1%
- CVE-2026-71322: Netflix Lemur missing authorization check on POST /certificates/<id>/exportmediumCVSS 4.3EPSS 0.2%
- CVE-2026-71317: Netflix Lemur sub-CA creation authorization bypassmediumCVSS 6.5EPSS 0.1%
- CVE-2026-71308: Netflix Lemur unchecked replaces authorization bypasshighCVSS 8.1EPSS 0.3%
- CVE-2026-71307: Netflix Lemur destinations API authorization bypasshighCVSS 7.7EPSS 0.3%
- CVE-2026-71303: Lemur ACME authority update endpoint SSRF via URL bypasshighCVSS 7.7EPSS 0.3%
- CVE-2026-70666: Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT…highCVSS 7.4EPSS 0.2%
- CVE-2026-70667: Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked…mediumCVSS 6.3EPSS 0.2%
- CVE-2026-55166: Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url…criticalCVSS 9.9EPSS 0.3%
- CVE-2026-55165: Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used…mediumCVSS 4.8EPSS 0.1%
- CVE-2026-55164: Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password…mediumCVSS 4.9EPSS 0.3%
- CVE-2026-55163: Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates…mediumCVSS 6.3EPSS 0.2%
- CVE-2026-55162: Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and…mediumCVSS 6.3EPSS 0.2%
- CVE-2026-48508: Netflix Lemur authorization bypass in permission classeshighCVSS 8.8EPSS 0.3%
- CVE-2026-44305: Netflix Lemur TLS certificate verification bypass in LDAP authenticationmediumCVSS 6.8EPSS 0.1%
- CVE-2026-44304: Netflix Lemur LDAP injection in authentication modulehighCVSS 8.1EPSS 0.3%
- CVE-2026-25534: Spinnaker clouddriver and orca URL validation bypass via underscorescriticalCVSS 9.1EPSS 0.4%
Most severe Netflix vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-55166: Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url…criticalCVSS 9.9EPSS 0.3%
- CVE-2026-25534: Spinnaker clouddriver and orca URL validation bypass via underscorescriticalCVSS 9.1EPSS 0.4%
- CVE-2026-48508: Netflix Lemur authorization bypass in permission classeshighCVSS 8.8EPSS 0.3%
- CVE-2026-71308: Netflix Lemur unchecked replaces authorization bypasshighCVSS 8.1EPSS 0.3%
- CVE-2026-44304: Netflix Lemur LDAP injection in authentication modulehighCVSS 8.1EPSS 0.3%
- CVE-2026-71307: Netflix Lemur destinations API authorization bypasshighCVSS 7.7EPSS 0.3%
- CVE-2026-71303: Lemur ACME authority update endpoint SSRF via URL bypasshighCVSS 7.7EPSS 0.3%
- CVE-2026-70666: Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT…highCVSS 7.4EPSS 0.2%
- CVE-2026-71417: Netflix Lemur arbitrary certificate revocation via duplicate uploadhighCVSS 7.3EPSS 0.1%
- CVE-2026-44305: Netflix Lemur TLS certificate verification bypass in LDAP authenticationmediumCVSS 6.8EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 13 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/netflix.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Netflix vulnerabilities", https://junglewise.ai/threats/vendors/netflix, 26 September 2026.