CVE-2019-17076: Jamf
Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.
An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro server.
Affected products
- Jamf Jamf: from 9.4, up to and including 9.101.4; from 10.0.0, up to and including 10.15.0
Published 2020-01-08. Last modified 2026-06-17.