Communications
8,215 CVEs tracked since 1999. In the last 12 months, 1,475, +112% on the 12 before.
Communications by subsector, Sep 2026 so far
- Email12261% · 8 vendors
- Messaging & chat4523% · 10 vendors
- VoIP & telephony2814% · 9 vendors
Also: Video conferencing 3, Not yet sub-classified 1.
Month by month
Every monthly snapshot of Communications. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 38 |
| 2021-10 | 27 |
| 2021-11 | 41 |
| 2021-12 | 54 |
| 2022-01 | 38 |
| 2022-02 | 41 |
| 2022-03 | 57 |
| 2022-04 | 44 |
| 2022-05 | 33 |
| 2022-06 | 67 |
| 2022-07 | 44 |
| 2022-08 | 37 |
| 2022-09 | 56 |
| 2022-10 | 28 |
| 2022-11 | 42 |
| 2022-12 | 51 |
| 2023-01 | 33 |
| 2023-02 | 21 |
| 2023-03 | 0 |
| 2023-04 | 37 |
| 2023-05 | 73 |
| 2023-06 | 56 |
| 2023-07 | 57 |
| 2023-08 | 62 |
| 2023-09 | 34 |
| 2023-10 | 71 |
| 2023-11 | 75 |
| 2023-12 | 68 |
| 2024-01 | 70 |
| 2024-02 | 67 |
| 2024-03 | 30 |
| 2024-04 | 49 |
| 2024-05 | 51 |
| 2024-06 | 28 |
| 2024-07 | 56 |
| 2024-08 | 77 |
| 2024-09 | 54 |
| 2024-10 | 54 |
| 2024-11 | 47 |
| 2024-12 | 28 |
| 2025-01 | 52 |
| 2025-02 | 56 |
| 2025-03 | 60 |
| 2025-04 | 89 |
| 2025-05 | 91 |
| 2025-06 | 53 |
| 2025-07 | 58 |
| 2025-08 | 53 |
| 2025-09 | 51 |
| 2025-10 | 54 |
| 2025-11 | 75 |
| 2025-12 | 186 |
| 2026-01 | 70 |
| 2026-02 | 79 |
| 2026-03 | 156 |
| 2026-04 | 89 |
| 2026-05 | 184 |
| 2026-06 | 156 |
| 2026-07 | 168 |
| 2026-08 | 207 |
| 2026-09 | 199 |
Vendors
Who shipped the most Communications CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Communications CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Communications.
- CVE-2026-100857AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation8.0
- CVE-2026-100856AzuraCast before 0.23.6 Code Injection via Remote Relay Password8.8
- CVE-2026-100855AzuraCast before 0.23.6 Missing Permission Check via /play6.5
- CVE-2026-100854AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API6.3
- CVE-2026-100853AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass5.9
- CVE-2026-100852AzuraCast through 0.23.x Command Injection via Streamer Username8.8
- CVE-2026-100851AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profile7.6
- CVE-2026-100850AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist7.7
- CVE-2026-100849AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs7.1
- CVE-2026-100848AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL7.1
- CVE-2026-100847AzuraCast before 0.23.8 DQL Injection via sortOrder7.5
- CVE-2026-100417RustDesk before 1.5.0 One-Way File Transfer Bypass3.1
- CVE-2026-100388RustDesk before 1.5.0 Missing Authorization Check on Incoming File Clipboard Messages5.4
- CVE-2026-94376Better Messages <= 3.0.4 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via User Display Name6.4
- CVE-2026-93899Better Messages <= 3.0.4 - Authenticated (Subscriber+) SQL Injection via 'group_id' Message Meta Parameter6.5
The record
- Busiest month
- Jun 2020, 214 CVEs
- Sep 2026 so far
- 199 CVEs from 30 vendors
- Deployment
- Mixed, 50%
- Monthly snapshots
- 296 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment