CVE Tools

Communications

8,215 CVEs tracked since 1999. In the last 12 months, 1,475, +112% on the 12 before.

Communications by subsector, Sep 2026 so far

Sep 2026 so far: 199 CVEs across 5 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • Email12261% · 8 vendors
  • Messaging & chat4523% · 10 vendors
  • VoIP & telephony2814% · 9 vendors

Also: Video conferencing 3, Not yet sub-classified 1.

Month by month

Every monthly snapshot of Communications. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Communications CVEs per month
MonthCVEs
2021-0938
2021-1027
2021-1141
2021-1254
2022-0138
2022-0241
2022-0357
2022-0444
2022-0533
2022-0667
2022-0744
2022-0837
2022-0956
2022-1028
2022-1142
2022-1251
2023-0133
2023-0221
2023-030
2023-0437
2023-0573
2023-0656
2023-0757
2023-0862
2023-0934
2023-1071
2023-1175
2023-1268
2024-0170
2024-0267
2024-0330
2024-0449
2024-0551
2024-0628
2024-0756
2024-0877
2024-0954
2024-1054
2024-1147
2024-1228
2025-0152
2025-0256
2025-0360
2025-0489
2025-0591
2025-0653
2025-0758
2025-0853
2025-0951
2025-1054
2025-1175
2025-12186
2026-0170
2026-0279
2026-03156
2026-0489
2026-05184
2026-06156
2026-07168
2026-08207
2026-09199

Vendors

Who shipped the most Communications CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Mattermost19#57
  2. Pjsip10#122
  3. Teluu8#147
  4. Simon Tatham7#171
  5. Cyrusimap6#179

Weaknesses

The weakness classes behind Communications CVEs in Sep 2026 so far.

  1. CWE-416 Use After Free28
  2. CWE-79 XSS13
  3. CWE-200 Information Exposure9
  4. CWE-862 Missing Authorization7
  5. CWE-269 Improper Privilege Mgmt7
  6. CWE-125 Out-of-bounds Read5

Latest CVEs

The 15 most recently published vulnerabilities in Communications.

  1. CVE-2026-100857AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation8.0
  2. CVE-2026-100856AzuraCast before 0.23.6 Code Injection via Remote Relay Password8.8
  3. CVE-2026-100855AzuraCast before 0.23.6 Missing Permission Check via /play6.5
  4. CVE-2026-100854AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API6.3
  5. CVE-2026-100853AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass5.9
  6. CVE-2026-100852AzuraCast through 0.23.x Command Injection via Streamer Username8.8
  7. CVE-2026-100851AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profile7.6
  8. CVE-2026-100850AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist7.7
  9. CVE-2026-100849AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs7.1
  10. CVE-2026-100848AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL7.1
  11. CVE-2026-100847AzuraCast before 0.23.8 DQL Injection via sortOrder7.5
  12. CVE-2026-100417RustDesk before 1.5.0 One-Way File Transfer Bypass3.1
  13. CVE-2026-100388RustDesk before 1.5.0 Missing Authorization Check on Incoming File Clipboard Messages5.4
  14. CVE-2026-94376Better Messages <= 3.0.4 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via User Display Name6.4
  15. CVE-2026-93899Better Messages <= 3.0.4 - Authenticated (Subscriber+) SQL Injection via 'group_id' Message Meta Parameter6.5

The record

Busiest month
Jun 2020, 214 CVEs
Sep 2026 so far
199 CVEs from 30 vendors
Deployment
Mixed, 50%
Monthly snapshots
296 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store