Back to the NordVPN review

Research record

What the public record says about NordVPN privacy and security

We read what auditors, courts, security researchers and the press have published about NordVPN, then kept only the claims that two separate sources back. This is a record of what is published, not a lab test.

Claims researched
31
Cleared for this page
8
Separate sources behind them
11
Research completed
October 3, 2026

What the evidence supports

Claims that two or more separate sources back

Each statement below is followed by the sources it rests on. A verdict describes what the sources say. It is not our endorsement.

Security reviews

Penetration tests and code reviews of the apps and servers.

Sources agree

Cure53 reviewed NordVPN's desktop and mobile apps and add-ons in July-August 2022 (report dated 22 Feb 2023): 22 findings, 6 of them vulnerabilities, including 1 Critical (Linux root privilege escalation) and High-severity macOS issues.

3 separate sources: Cure53, NordVPN, and CyberInsider

Sources and caveats (3)
  1. Cure53 · Audit report · Published February 22, 2023

    identifying a total of twenty-two. Six of the findings were categorized as security vulnerabilities, whilst the remaining sixteen were deemed general weaknesses with lower exploitation potential.

    Counts toward the two-source rule

  2. NordVPN (nordvpn.com blog) · Provider own statement · Published February 28, 2023

    All the detected critical, high, and medium severity vulnerabilities were fixed by our restless developers and approved by the Cure53 authority

    Counts toward the two-source rule

  3. CyberInsider · Press report · Published March 2, 2023

    The relatively typical volume of vulnerabilities detected for a scope of this magnitude indicates that the entire client software complex has already made strong progress from a security perspective.

    Counts toward the two-source ruleQuote not yet re-checked against the page

Researcher notes

Primary document read in full. The 'fixed and approved' claim is Nord's; the Cure53 report is the pre-fix state. Nord says all critical/high/medium issues were fixed; the later 2024 report lists 'NOR-15-002 Unpatched vulnerabilities from previous test (Medium)', so at least one earlier finding persisted to mid-2024. The Cure53 conclusion for this scope is 'a mixed impression, with security strengths and weaknesses detected across all work packages'. Sponsor-paid audit.

Sources agree

Cure53 reviewed NordVPN's servers and infrastructure in September-October 2022 (report dated 5 Feb 2023): 11 findings, 1 vulnerability, and concluded the servers exhibit a 'relatively stable security foundation'.

2 separate sources: Cure53 and NordVPN

Sources and caveats (2)
  1. Cure53 · Audit report · Published February 5, 2023

    the Cure53 team is pleased to confirm that the NordVPN servers and infrastructure exhibit a relatively stable security foundation.

    Counts toward the two-source rule

  2. NordVPN (nordvpn.com blog) · Provider own statement · Published February 28, 2023

    Cure53 conducted a penetration test and source code audit against the NordVPN servers, infrastructure, and NordVPN desktop applications for Windows, Linux, and macOS.

    Counts toward the two-source rule

Researcher notes

Two groups (Cure53 primary, Nord). The report is a white-box review by four testers, scope 'single scope item'. One Low finding: 'Critical components persist unpatched CVEs'. Cure53's own wording is measured ('relatively stable', 'plenty of opportunity for security growth'), noticeably less promotional than Nord's summary.

Sources agree

Cure53's mid-2024 review of NordVPN's apps, browser extensions and features (report dated 17 Dec 2024; 55 working days, 11 testers) found 31 issues, of which 22 were vulnerabilities and 4 were High severity, with no Critical findings.

3 separate sources: Cure53, NordVPN, and CyberInsider

Sources and caveats (3)
  1. Cure53 (copy hosted on NordVPN's CDN, sb.nordcdn.com) · Audit report · Published December 17, 2024

    identified a total of thirty-one findings. Of the thirty-one security-related discoveries, twenty-two were classified as security vulnerabilities, and nine were categorized as general weaknesses

    Counts toward the two-source rule

    Conflict of interest: Report is commissioned and paid for by Nord Security; file served from Nord's CDN

  2. NordVPN (nordvpn.com blog) · Provider own statement · Published March 4, 2025

    The assessment began in June 2024 and lasted 55 working days.

    Counts toward the two-source rule

  3. CyberInsider · Press report · Published March 6, 2025

    a total of 31 security issues, with four rated as high severity

    Counts toward the two-source ruleQuote not yet re-checked against the page

Researcher notes

Primary document read. The four High items (NOR-15-001, -006, -007, -023) include a VPN-bypass for certain top-level domains and a Threat Protection TLS-validation gap. Cure53's own wording: 'the current implementation is one remote-code-execution (RCE) vulnerability away from becoming a tunneled command and control (C2) infrastructure' (Meshnet scope). Nord's post frames the result as 'no critical risks'. The PDF is hosted on Nord's CDN, not cure53.de: provenance is Nord's. Whether the High findings were fixed is Nord's claim; CyberInsider says Cure53 verified the fixes (summarised read, unverified). A TechRadar line mentions Cure53 work 'in May, June and October' of 2025 and a West Coast Labs test; neither was located as a separate report, so not recorded.

Servers and protocols

How the servers and connection protocols are built.

Sources agree

NordLynx is NordVPN's WireGuard-based protocol, and Cure53's 2022 infrastructure review assessed Nord's patched WireGuard kernel module and found no issues.

2 separate sources: NordVPN and Cure53

Sources and caveats (2)
  1. NordVPN (nordvpn.com blog) · Provider own statement · Published January 29, 2026

    Developed by NordVPN on the WireGuard framework, NordLynx offers a high-speed, secure VPN connection

    Counts toward the two-source rule

  2. Cure53 · Audit report · Published February 5, 2023

    the provided patch files for the Radius server and Wireguard kernel module were assessed for potential memory corruptions or authentication-related flaws. Positively, no associated issues were identified here.

    Counts toward the two-source rule

Researcher notes

Two independent groups for the narrow statement. The report text says 'Wireguard kernel module', not 'NordLynx', so the link to the named protocol is Nord's. 2022 findings cover host and container configuration; the review is dated (Sept-Oct 2022).

Incidents and vulnerabilities

Breaches and published software flaws, and how they came to light.

Sources agree

One NordVPN server at a third-party datacentre in Finland was accessed without authorisation in March 2018 via an insecure remote-management system the datacentre had left, and a TLS key and OpenVPN configuration files were taken and leaked.

3 separate sources: NordVPN, TechCrunch, and BleepingComputer

Sources and caveats (3)
  1. NordVPN (nordvpn.com blog) · Provider own statement · Published October 21, 2019

    One server was affected in March 2018 in Finland. The rest of our service was not affected.

    Counts toward the two-source rule

  2. TechCrunch · Press report · Published October 21, 2019

    The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the data center provider; NordVPN said it was unaware that such a system existed.

    Counts toward the two-source rule

  3. BleepingComputer · Press report · Published October 21, 2019

    Servers belonging to the NordVPN and TorGuard VPN companies were hacked and attackers stole and leaked the private keys associated with certificates used to secure their web servers and VPN configuration files.

    Counts toward the two-source rule

    Conflict of interest: Page discloses: 'BleepingComputer is an affiliate of NordVPN.'

Researcher notes

Three groups, but all three lean on Nord's statement for the mechanism. BleepingComputer saw the leaked key material first-hand (via a researcher's tweet and an 8chan post) and discloses it is a NordVPN affiliate. TechCrunch did not independently verify and cites an anonymous researcher. TorGuard and VikingVPN were hit by the same actor. The TLS key's expiry and its inability to decrypt VPN traffic are Nord's assertions (CryptoStorm disputed the traffic point per BleepingComputer).

Sources agree

NordVPN publicly disclosed the breach on 21 October 2019, about 19 months after the March 2018 intrusion and after a leaked key surfaced online; Nord says it learned of the breach on 13 April 2019.

3 separate sources: NordVPN, TechCrunch, and BleepingComputer

Sources and caveats (3)
  1. NordVPN (nordvpn.com blog) · Provider own statement · Published October 21, 2019

    We were notified about the breach on April 13, 2019. We shredded the server that same day.

    Counts toward the two-source rule

  2. TechCrunch · Press report · Published October 21, 2019

    NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.”

    Counts toward the two-source rule

  3. BleepingComputer · Press report · Published October 21, 2019

    Over the weekend, security researcher tweeted that NordVPN, of which we are an affiliate, was compromised as the private keys for their web site certificate were publicly leaked on the Internet.

    Counts toward the two-source rule

    Conflict of interest: Page discloses: 'BleepingComputer is an affiliate of NordVPN.'

Researcher notes

The disclosure date is firm (three dated posts). The 'learned April 2019' date and the 'we waited to audit' rationale are Nord's alone (not independently confirmed); TechCrunch's 'few months ago' agrees in direction only. Public disclosure followed a researcher's tweet over the weekend of 19-20 Oct 2019 (BleepingComputer), so the framing 'we chose to disclose after the audit' is Nord's, and the leak preceded it.

Sources agree

The NVD lists six NordVPN client CVEs: three published in 2018 (CVE-2018-9105 macOS, CVE-2018-10170 Windows, CVE-2018-3952 Windows) and three published in 2026 as backfills for old client versions (CVE-2018-25368, CVE-2019-25572, CVE-2020-36992).

2 separate sources: NIST National Vulnerability Database and NordVPN

Sources and caveats (3)
  1. NIST National Vulnerability Database · Legal or government record · No publication date stated

    NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service.

    Counts toward the two-source rule

  2. Cisco Talos · Audit report · Published September 7, 2018

    An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0.

    Counts toward the two-source ruleQuote not yet re-checked against the page

  3. NordVPN (nordvpn.com blog) · Provider own statement · Published September 10, 2018

    The vulnerability described in their report no longer exists on our systems.

    Counts toward the two-source rule

Researcher notes

Counts: NVD CPE query returned 4 records (CVE-2018-9105, -10170, -3952, 2019-25572); keyword search 'nordvpn' returned 5 (adding CVE-2020-36992); CVE-2018-25368 was found by id after a search aggregator named it. Six distinct records in total. NVD severities seen: CVE-2018-10170 CVSS v3.0 9.8 (v2 10.0); CVE-2018-9105 v3.0 8.8; CVE-2018-3952 v3.1 8.8. The three 2026 records are VulnCheck backfills of old client versions (6.14.31, 6.19.6, 6.31.13.0), not new discoveries. Talos CVE-2018-3952: per a summarised read, vendor notified 2018-07-05, patch confirmed 2018-08-08, public 2018-09-07 (not re-read raw). Nord says the flaw needed an already-compromised machine. 'Independent' groups here are Talos/NVD (one, NVD derives the Talos record) and Nord. Counting vulnerabilities in a client is not a negative signal on its own: every large client has them; the NVD count is an inventory, not a score.

Court cases and legal demands on the provider.

Sources agree

The US class actions filed against NordVPN in 2025 (S.D.N.Y., N.D. Ill.; also reported in other districts) allege deceptive automatic-renewal and cancellation practices; a text search of both complaints finds no allegation about Nord's privacy or no-logs claims.

2 separate sources: US District Court, Southern District of New York and US District Court, Northern District of Illinois

Sources and caveats (2)
  1. US District Court, Southern District of New York (copy hosted by Truth in Advertising) · Legal or government record · Published March 28, 2025

    This proposed class action lawsuit challenging Nord Security’s use of deceptive and illegal “automatic renewal” tactics to trick consumers into paying for unwanted, pricey subscriptions

    Counts toward the two-source rule

    Conflict of interest: Plaintiff's pleading: allegations only, none adjudicated

  2. US District Court, Northern District of Illinois (copy hosted by classaction.org) · Legal or government record · Published June 20, 2025

    This proposed class action lawsuit challenges Nord Security’s use of deceptive and illegal “automatic renewal” tactics to trick consumers into paying for unwanted subscriptions

    Counts toward the two-source rule

    Conflict of interest: Plaintiff's pleading: allegations only, none adjudicated

Researcher notes

Two independent court filings (different plaintiffs and courts, same counsel in both), so the existence of the suits is 2-source. They are allegations only. Their subject is billing, not privacy: that is a trust-relevant fact for 'consumer practices' but is not evidence on the privacy and security record. Other districts (N.D. Cal., W.D.N.C., Colorado, Virginia, Connecticut) are reported in search results and not verified. Outcomes unknown.

What we cannot yet show

Where the record is thin

A claim stays off this page until two separate sources back it and an editor has cleared its wording. Each dot is one claim we researched. A filled dot is on this page. A hollow dot is not, yet.

  • Logging and no-logs audits0 of 7 shown
  • Security reviews3 of 4 shown
  • Servers and protocols1 of 4 shown
  • Ownership and jurisdiction0 of 3 shown
  • Incidents and vulnerabilities3 of 6 shown
  • Legal actions1 of 5 shown
  • Transparency0 of 2 shown

Not shown means one of two things: fewer than two separate sources, or still waiting for an editor to settle the wording or check a document. It does not mean the claim is false.

How this feeds the Trust Score

The evidence trail behind the number

The Trust Score has a criterion for security track record: audits, breaches and incidents. This page is the written trail for that kind of question, showing what was published, by whom, and how many separate sources agree.

Points are still assigned by the published formula. Read how in the methodology.

How the Trust Score works

How we research

Four rules we hold ourselves to

  1. Two separate sources, minimum

    Two outlets repeating one press release count as one source. Independence is decided by where the information came from, not by how many sites carry it.

  2. Primary documents first

    Auditor reports, court filings and regulator records come before commentary. A provider own page is evidence of what the provider says, never proof that it is true.

  3. Nothing found is a result

    When a search turns up nothing we record what we searched. We never present an empty search as a clean bill of health.

  4. No softening for partners

    A finding that the evidence qualifies is recorded as qualified, whoever the provider is.

VPN.com does not run its own testing lab. Every audit listed here was commissioned and paid for by the provider it examined, and we say so where it applies. We earn commission from some providers; see our disclosures.Read our disclosures