Vendor
Roxy-WI vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 14 vulnerabilities in Roxy-WI: 0 in the last 7 days and 0 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-45569, was published on 10 June 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 4
- Exploited in the wild
- 0
About Roxy-WI
Roxy-WI provides open-source solutions for managing and monitoring load balancers and web servers.
Roxy-WI technologies
- Roxy-WI14
Latest Roxy-WI vulnerabilities
- CVE-2026-45569: Roxy-WI path traversal in configuration managementhighCVSS 8.1
- CVE-2026-45567: Roxy-WI authentication bypass via URL substring manipulationhighCVSS 8.3
- CVE-2026-45566: Roxy-WI open redirect in login flow via userinfo syntax bypassmediumCVSS 6.1
- CVE-2026-45565: Roxy-WI input validation bypass in EscapedString validatorhighCVSS 8.1
- CVE-2026-45564: Roxy-WI command injection in config versions save routehighCVSS 8.8
- CVE-2026-45563: Roxy-WI authorization bypass in history endpointmediumCVSS 4.3
- CVE-2026-45561: Roxy-WI SSRF in SMON agent routesmediumCVSS 6.5
- CVE-2026-45560: Roxy-WI stored XSS in log viewermediumCVSS 6.1
- CVE-2026-45559: Roxy-WI LDAP injection in get_ldap_emailmediumCVSS 4.9
- CVE-2026-45558: Roxy-WI command injection in HAProxy section-save endpointscriticalCVSS 9.9
- CVE-2026-45556: Roxy-WI authenticated arbitrary file write in WAF rule savecriticalCVSS 9.9
- CVE-2026-45552: Roxy-WI authorization bypass in install blueprintcriticalCVSS 9.9
- CVE-2026-45550: Roxy-WI IDOR in SMON monitoring check updatecriticalCVSS 9.1
- CVE-2026-45549: Roxy-WI authorization bypass in SMON agent actionhighCVSS 8.5
Most severe Roxy-WI vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-45558: Roxy-WI command injection in HAProxy section-save endpointscriticalCVSS 9.9
- CVE-2026-45556: Roxy-WI authenticated arbitrary file write in WAF rule savecriticalCVSS 9.9
- CVE-2026-45552: Roxy-WI authorization bypass in install blueprintcriticalCVSS 9.9
- CVE-2026-45550: Roxy-WI IDOR in SMON monitoring check updatecriticalCVSS 9.1
- CVE-2026-45564: Roxy-WI command injection in config versions save routehighCVSS 8.8
- CVE-2026-45549: Roxy-WI authorization bypass in SMON agent actionhighCVSS 8.5
- CVE-2026-45567: Roxy-WI authentication bypass via URL substring manipulationhighCVSS 8.3
- CVE-2026-45569: Roxy-WI path traversal in configuration managementhighCVSS 8.1
- CVE-2026-45565: Roxy-WI input validation bypass in EscapedString validatorhighCVSS 8.1
- CVE-2026-45561: Roxy-WI SSRF in SMON agent routesmediumCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/roxy-wi.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Roxy-WI vulnerabilities", https://junglewise.ai/threats/vendors/roxy-wi, 26 September 2026.