Cloud & SaaS
12,560 CVEs tracked since 1999. In the last 12 months, 3,427, +165% on the 12 before.
Cloud & SaaS by subsector, Sep 2026 so far
- SaaS applications15737% · 24 vendors
- Cloud platforms10224% · 17 vendors
- Container orchestration10124% · 19 vendors
- Virtualization276% · 6 vendors
- API gateways205% · 6 vendors
- Not yet sub-classified14The tagger has not placed these yet
Month by month
Every monthly snapshot of Cloud & SaaS. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 70 |
| 2021-10 | 55 |
| 2021-11 | 51 |
| 2021-12 | 50 |
| 2022-01 | 65 |
| 2022-02 | 65 |
| 2022-03 | 105 |
| 2022-04 | 83 |
| 2022-05 | 73 |
| 2022-06 | 96 |
| 2022-07 | 99 |
| 2022-08 | 76 |
| 2022-09 | 76 |
| 2022-10 | 84 |
| 2022-11 | 120 |
| 2022-12 | 75 |
| 2023-01 | 71 |
| 2023-02 | 68 |
| 2023-03 | 0 |
| 2023-04 | 87 |
| 2023-05 | 86 |
| 2023-06 | 80 |
| 2023-07 | 108 |
| 2023-08 | 129 |
| 2023-09 | 74 |
| 2023-10 | 87 |
| 2023-11 | 131 |
| 2023-12 | 84 |
| 2024-01 | 123 |
| 2024-02 | 59 |
| 2024-03 | 96 |
| 2024-04 | 129 |
| 2024-05 | 96 |
| 2024-06 | 94 |
| 2024-07 | 122 |
| 2024-08 | 64 |
| 2024-09 | 112 |
| 2024-10 | 82 |
| 2024-11 | 146 |
| 2024-12 | 89 |
| 2025-01 | 104 |
| 2025-02 | 99 |
| 2025-03 | 78 |
| 2025-04 | 137 |
| 2025-05 | 115 |
| 2025-06 | 121 |
| 2025-07 | 97 |
| 2025-08 | 113 |
| 2025-09 | 135 |
| 2025-10 | 78 |
| 2025-11 | 122 |
| 2025-12 | 172 |
| 2026-01 | 140 |
| 2026-02 | 155 |
| 2026-03 | 254 |
| 2026-04 | 216 |
| 2026-05 | 400 |
| 2026-06 | 402 |
| 2026-07 | 484 |
| 2026-08 | 869 |
| 2026-09 | 421 |
Vendors
Who shipped the most Cloud & SaaS CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Cloud & SaaS CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Cloud & SaaS.
- CVE-2026-100746coollabsio Coolify GitHub App Setup redirect missing authentication7.3
- CVE-2026-100744coollabsio Coolify Route-Level Middleware CanUpdateResource.php authorization7.3
- CVE-2026-100707Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path7.7
- CVE-2026-100706kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath9.9
- CVE-2026-100705Kyverno before 1.19.1 SSRF via legacy apiCall service executor7.6
- CVE-2026-100704Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass7.7
- CVE-2026-100703Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib7.7
- CVE-2026-100688Budibase server before 3.45.0 Cross-Tenant Information Disclosure6.5
- CVE-2026-100687Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast5.5
- CVE-2026-100686Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/apps8.1
- CVE-2026-100684Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC8.1
- CVE-2026-100685Budibase before 3.45.0 Information Disclosure via Chat Links7.7
- CVE-2026-100683Budibase before 3.45.0 SQL Injection via column-rename DDL8.0
- CVE-2026-100681Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook5.4
- CVE-2026-100682Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink8.8
The record
- Busiest month
- Aug 2026, 869 CVEs
- Sep 2026 so far
- 421 CVEs from 79 vendors
- Deployment
- Mixed, 57%
- Monthly snapshots
- 268 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment