Skip to content
COOEY

FAIL › dossier

SysAid

VENDOR

· dossier confidence 40%

SysAid, a provider of IT service management software, has experienced significant security vulnerabilities, including critical remote code execution flaws, which have been exploited for ransomware attacks.

PROFILE
CategoryIT Service Management (ITSM) SoftwareWhat they doSysAid Technologies Ltd. provides IT service management (ITSM) software used by IT teams to manage service requests and incidents. The platform includes a service desk, self-service portal, knowledge base, workflow automation, and IT asset management tools. SysAid is available as cloud and on-premises deployments.Founded2013 Websitehttps://sysaid.com ↗
SECURITY POSTURE

SysAid has faced multiple security vulnerabilities, including XML entity reference vulnerabilities and path traversal flaws, which have been exploited for remote code execution and ransomware attacks.

Notable failures
  • CVE-2025-2776 (High [RCE])
  • CVE-2023-47246 (Critical [RCE])
  • CVE-2025-2775 (High [RCE])
Patterns: Repeated unpatched edge-device RCEs; Remote code execution through server path traversal
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2025-07-22 CVE-2025-2776 high SysAid On-Prem suffered XML entity reference vulnerability leading to admin takeover and file reads
2023-11-13 CVE-2023-47246 critical SysAid Server's path traversal flaw allowed remote code execution, directly enabling ransomware attacks.
2025-07-22 CVE-2025-2775 high SysAid On-Prem allowed XML External Entity Reference, enabling admin takeover and file reads
2023-11-10 CVE-2023-47246 critical CVE-2023-47246: In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to cod
2023-11-10 CVE-2023-47246 critical CVE-2023-47246: In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to cod
Open questions: Does SysAid have a robust security posture? · How does SysAid address and communicate its security vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-27 03:41:58.467705+00:00