Secure Enterprise Operations Platform

Vulnerability Management

Findings tracked to a named owner with severity-based remediation SLAs (NIST SP 800-171 Rev. 3 — 03.11.02).

12 findings

SLA breaches are highlighted. Data is synthetic; synthetic vulnerability identifiers, not real CVEs.

IDIdentifierTitleSeverityCVSSAffected assetsStatusDiscoveredOwnerSLA due
VLN-2001SYN-2026-10041Remote code execution in HTTP parsing librarycritical9.8AST-1001, AST-1002, AST-1015in progress2026-08-04Platform Engineering2026-08-11 · breached
VLN-2002SYN-2026-10188Privilege escalation via unsafe setuid helpercritical9.1AST-1004open2026-08-07Data Platform2026-08-14
VLN-2003SYN-2026-10222Authentication bypass in session refresh flowcritical8.9AST-1003in progress2026-08-08Identity Services2026-08-15
VLN-2004SYN-2026-10310Improper certificate validation in outbound clienthigh7.9AST-1006, AST-1015open2026-08-05Cloud Operations2026-08-19
VLN-2005SYN-2026-10388Stored cross-site scripting in reporting consolehigh7.4AST-1011in progress2026-08-02Analytics2026-08-16
VLN-2006SYN-2026-10402Excessive IAM permissions on deployment rolehigh7.2AST-1007mitigated2026-07-28DevSecOps2026-08-11
VLN-2007SYN-2026-10455Outdated TLS cipher suites enabled on edge listenermedium6.1AST-1001, AST-1002open2026-08-09Network Security2026-08-30
VLN-2008SYN-2026-10501Verbose error responses leak stack tracesmedium5.4AST-1015in progress2026-08-03Platform Engineering2026-08-24
VLN-2009SYN-2026-10577Missing rate limiting on password reset endpointmedium5.9AST-1003open2026-08-10Identity Services2026-09-01
VLN-2010SYN-2026-10611Unencrypted local diagnostic cachelow3.3AST-1009, AST-1010accepted2026-07-21Security Operations2026-09-15
VLN-2011SYN-2026-10644Deprecated dependency with no known exploit pathlow2.8AST-1014open2026-08-06Engineering Enablement2026-09-20
VLN-2012SYN-2026-10702Secrets proxy audit logging gap under loadhigh7.6AST-1013open2026-08-11Security Engineering2026-08-25