Known vulnerabilities in Two Factor
Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email, and backup verification codes.
1Reported vulnerabilities
7.5Highest CVSS score
0.17.0Latest version
100,000+Active installs
What to do now
Update Two Factor to 0.17.0 or later.
1 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-100508 | High | — | 0.16.0 and earlier | 0.17.0 |
September 30, 2026 |