CVE Tools

Cloud & SaaS

12,560 CVEs tracked since 1999. In the last 12 months, 3,427, +165% on the 12 before.

Cloud & SaaS by subsector, Sep 2026 so far

Sep 2026 so far: 421 CVEs across 6 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • SaaS applications15737% · 24 vendors
  • Cloud platforms10224% · 17 vendors
  • Container orchestration10124% · 19 vendors
  • Virtualization276% · 6 vendors
  • API gateways205% · 6 vendors
  • Not yet sub-classified14The tagger has not placed these yet

Month by month

Every monthly snapshot of Cloud & SaaS. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Cloud & SaaS CVEs per month
MonthCVEs
2021-0970
2021-1055
2021-1151
2021-1250
2022-0165
2022-0265
2022-03105
2022-0483
2022-0573
2022-0696
2022-0799
2022-0876
2022-0976
2022-1084
2022-11120
2022-1275
2023-0171
2023-0268
2023-030
2023-0487
2023-0586
2023-0680
2023-07108
2023-08129
2023-0974
2023-1087
2023-11131
2023-1284
2024-01123
2024-0259
2024-0396
2024-04129
2024-0596
2024-0694
2024-07122
2024-0864
2024-09112
2024-1082
2024-11146
2024-1289
2025-01104
2025-0299
2025-0378
2025-04137
2025-05115
2025-06121
2025-0797
2025-08113
2025-09135
2025-1078
2025-11122
2025-12172
2026-01140
2026-02155
2026-03254
2026-04216
2026-05400
2026-06402
2026-07484
2026-08869
2026-09421

Vendors

Who shipped the most Cloud & SaaS CVEs in Sep 2026 so far, with their rank across all vendors.

  1. N8N-IO28#40
  2. N8N25#46
  3. Aws18#60
  4. Go-vikunja13#92
  5. Webpros13#94
  6. Amazon9#124
  7. 1panel-dev7#153
  8. Envoyproxy7#158

Weaknesses

The weakness classes behind Cloud & SaaS CVEs in Sep 2026 so far.

  1. CWE-125 Out-of-bounds Read32
  2. CWE-862 Missing Authorization28
  3. CWE-122 Heap Buffer Overflow26
  4. CWE-22 Path Traversal25
  5. CWE-639 Auth Bypass via User Key18
  6. CWE-284 Improper Access Control14

Latest CVEs

The 15 most recently published vulnerabilities in Cloud & SaaS.

  1. CVE-2026-100746coollabsio Coolify GitHub App Setup redirect missing authentication7.3
  2. CVE-2026-100744coollabsio Coolify Route-Level Middleware CanUpdateResource.php authorization7.3
  3. CVE-2026-100707Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path7.7
  4. CVE-2026-100706kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath9.9
  5. CVE-2026-100705Kyverno before 1.19.1 SSRF via legacy apiCall service executor7.6
  6. CVE-2026-100704Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass7.7
  7. CVE-2026-100703Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib7.7
  8. CVE-2026-100688Budibase server before 3.45.0 Cross-Tenant Information Disclosure6.5
  9. CVE-2026-100687Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast5.5
  10. CVE-2026-100686Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/apps8.1
  11. CVE-2026-100684Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC8.1
  12. CVE-2026-100685Budibase before 3.45.0 Information Disclosure via Chat Links7.7
  13. CVE-2026-100683Budibase before 3.45.0 SQL Injection via column-rename DDL8.0
  14. CVE-2026-100681Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook5.4
  15. CVE-2026-100682Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink8.8

The record

Busiest month
Aug 2026, 869 CVEs
Sep 2026 so far
421 CVEs from 79 vendors
Deployment
Mixed, 57%
Monthly snapshots
268 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store