Mitel vendor intelligence
Mitel Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Mitel products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 9
- Known exploited vulnerabilities affecting Mitel products
- In CISA KEV
- 7
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Mitel KEVs with sensor-observed exploitation activity
The catalog gap matters for Mitel exposure
Two of the nine exploited Mitel CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 22% of this vendor portfolio.
- 78%
- Covered by CISA
- 22%
- Beyond CISA
- 6
- Product families
Attested Mitel CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-47188
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit... |
6800 Series, 6900 Series, 6900w Series SIP Phones, 6970 Conference Unit | High | Beyond CISA | 09 Mar 2026 |
|
CVE-2022-26143
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain... |
MiCollab, MiVoice Business Express | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-29499
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The... |
MiVoice Connect | Confirmed | In CISA | 27 Jun 2022 |
|
CVE-2022-40765
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with... |
MiVoice Connect | Confirmed | In CISA | 21 Feb 2023 |
|
CVE-2022-41223
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection... |
MiVoice Connect | Confirmed | In CISA | 21 Feb 2023 |
|
CVE-2024-41713
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated... |
MiCollab | Confirmed | In CISA | 07 Jan 2025 |
|
CVE-2024-55550
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to... |
MiCollab | Confirmed | In CISA | 07 Jan 2025 |
|
CVE-2024-41710
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1... |
6800 Series, 6900 Series, 6900w Series SIP Phones, including the 6970 Conference Unit | Confirmed | In CISA | 12 Feb 2025 |
|
CVE-2020-11798
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an... |
MiCollab AWV | High | Beyond CISA | 10 Jun 2020 |
No Mitel CVEs match this search or filter.
Showing 9 of 9 Mitel known exploited vulnerabilities.
Recurring weakness patterns
Limitation, neutralization, and input validation account for six mapped occurrences across this Mitel KEV portfolio.
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-20
Improper Input Validation
CWE-306
Missing Authentication for Critical Function
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CWE-94
Improper Control of Generation of Code ('Code Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.