Cleo A.I CyberSecurity Scoring
Cleo
Company Information
Website:https://www.cleo.com
Employees number:583
Number of followers:14,924
NAICS:5112
Industry Type:Software Development
Homepage:cleo.com
Cleo Risk Score (AI oriented)
Between 600 and 649
CleoSoftware Development
Updated:
03/09/2026
03/09/2026
634/1000
Poor
Caa
Cleo Global Score (TPRM)
xxxx
CleoSoftware Development
Score locked

CleoPoor
Current Score
634Caa (POOR)
01000
3 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
638
Vulnerability
01 Sep 2026 • Cleo
Cleo: CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
Critical Privilege Escalation Vulnerability in Cleo Harmony (CVE-2026-84115)
634
CRITICAL-4
CLE1788431185
Critical Privilege Escalation Vulnerability in Cleo Harmony (CVE-2026-84115) Exposes Systems to Remote Exploitation
A severe privilege-management vulnerability, tracked as CVE-2026-84115, has been identified in Cleo Harmony versions up to 5.8.1.10, affecting the platform’s JWT Refresh Token Handler and the `/api/connections` endpoint. Disclosed by MITRE on September 1, 2026, and classified by VulDB (VDB-397558) as a CWE-269 (Improper Privilege Management) flaw, the vulnerability carries a CVSS score of 8.3, indicating high severity.
The flaw stems from an unknown function in the JWT Refresh Token Handler, where manipulation of the Bearer token argument in HTTP authorization headers can lead to authentication bypass. Attackers exploiting this weakness could escalate privileges, gaining unauthorized administrative access, viewing sensitive data, or disrupting integration workflows managed through Cleo Harmony. The vulnerability is remotely exploitable via network-based HTTP requests, increasing its risk profile particularly as a public exploit has been reported.
Successful exploitation could compromise confidentiality, integrity, and availability of systems relying on Cleo Harmony for file transfers and API connectivity. Attackers may intercept legitimate traffic or forge requests using malformed or replayed bearer tokens, potentially enabling lateral movement across connected environments.
Remediation requires upgrading to Cleo Harmony version 5.8.1.11 or later, which addresses the privilege-management flaw. While interim measures such as enhanced input validation and bearer token monitoring may reduce exposure, they do not substitute for patching, given the availability of a public exploit. The vulnerability has been assigned an EPSS score of 0.00284, reflecting its exploitability risk.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
637
JULY 2026
635
JUNE 2026
633
MAY 2026
628
APRIL 2026
626
MARCH 2026
626
FEBRUARY 2026
623
JANUARY 2026
621
DECEMBER 2025
618
NOVEMBER 2025
615
OCTOBER 2025
613
AUGUST 2025
717
Ransomware
01 Aug 2025 • Cleo
Oracle
Clop Ransomware Exploits Oracle E-Business Suite Zero-Day (CVE-2025-61882) in Data Theft Attacks
604
CRITICAL-113
ORA1692116100725
The Clop ransomware gang exploited a critical zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite (EBS), specifically within the BI Publisher Integration component, to conduct data theft attacks since at least August 2025. The flaw allowed unauthenticated remote code execution (RCE) via a single HTTP request, enabling attackers to steal sensitive corporate documents from unpatched systems. Oracle patched the vulnerability in early October 2025, but not before Clop launched an extortion campaign, emailing executives at multiple victim organizations to demand ransoms in exchange for not leaking the stolen data.The attack leveraged a vulnerability chain exposed by leaked proof-of-concept (PoC) exploits from the Scattered Lapsus$ Hunters group, increasing the risk of further exploitation by other threat actors. Clop’s campaign mirrors past high-profile breaches, including MOVEit Transfer (2,770+ organizations affected), Accellion FTA, and GoAnywhere MFT, reinforcing its reputation for large-scale data theft via zero-days. Oracle urged immediate patching, warning that internet-exposed EBS applications remain prime targets. The U.S. State Department has even offered a $10 million reward for intelligence linking Clop to foreign state sponsorship, underscoring the attack’s severity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2022
755
Breach
28 Oct 2022 • Cleo
Cleo Communications US, LLC
Cleo Communications US, LLC Data Breach
682
CRITICAL-73
CLE047080525
The Maine Office of the Attorney General reported that Cleo Communications US, LLC experienced an external system breach (hacking) that began on October 28, 2022, and was discovered on February 8, 2023. Approximately 644 individuals were affected, including one Maine resident, and personal information, including Social Security numbers, may have been exposed. Written notices were sent on April 14, 2023, and credit monitoring and identity restoration services were offered for 24 months.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Cleo ??
What was Cleo's A.I Rankiteo Cyber Score in August 2026 ??
What was Cleo's A.I Rankiteo Cyber Score in July 2026 ??
What was Cleo's A.I Rankiteo Cyber Score in June 2026 ??
What was Cleo's A.I Rankiteo Cyber Score in May 2026 ??
What was Cleo's A.I Rankiteo Cyber Score in April 2026 ??
What was Cleo's A.I Rankiteo Cyber Score in March 2026 ??
What was Cleo's A.I Rankiteo Cyber Score in February 2026 ??
What was Cleo's A.I Rankiteo Cyber Score in January 2026 ??
What was Cleo's A.I Rankiteo Cyber Score in December 2025 ??
What was Cleo's A.I Rankiteo Cyber Score in November 2025 ??
What was Cleo's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Cleo's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Cleo ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Cleo's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?