CVE Tools

Hardware & Firmware

14,893 CVEs tracked since 1999. In the last 12 months, 2,446, +19% on the 12 before.

Hardware & Firmware by subsector, Sep 2026 so far

Sep 2026 so far: 269 CVEs across 6 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • Network adapters10138% · 8 vendors
  • Not yet sub-classified79The tagger has not placed these yet
  • CPUs & GPUs5621% · 8 vendors
  • BIOS & UEFI166% · 6 vendors
  • Storage & NAS145% · 2 vendors
  • Printers & peripherals31% · 1 vendor

Month by month

Every monthly snapshot of Hardware & Firmware. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Hardware & Firmware CVEs per month
MonthCVEs
2021-0990
2021-1071
2021-11154
2021-1227
2022-01166
2022-02165
2022-0360
2022-04113
2022-05176
2022-06147
2022-0784
2022-08143
2022-09137
2022-10109
2022-11190
2022-12162
2023-01258
2023-02319
2023-030
2023-04180
2023-05327
2023-06170
2023-07195
2023-08264
2023-09192
2023-10152
2023-11312
2023-12219
2024-01208
2024-02248
2024-03148
2024-04150
2024-05174
2024-06119
2024-07113
2024-08182
2024-09144
2024-10118
2024-11243
2024-12143
2025-01127
2025-02211
2025-03160
2025-04123
2025-05167
2025-06212
2025-07166
2025-08240
2025-09173
2025-10187
2025-11205
2025-12194
2026-01235
2026-02255
2026-03174
2026-0496
2026-05215
2026-06186
2026-07155
2026-08371
2026-09269

Vendors

Who shipped the most Hardware & Firmware CVEs in Sep 2026 so far, with their rank across all vendors.

  1. HPE129#10
  2. Nvidia32#34
  3. Mediatek, Inc.18#61
  4. Asus12#97
  5. Arm Ltd10#117

Weaknesses

The weakness classes behind Hardware & Firmware CVEs in Sep 2026 so far.

  1. CWE-269 Improper Privilege Mgmt22
  2. CWE-200 Information Exposure13
  3. CWE-863 Incorrect Authorization9
  4. CWE-284 Improper Access Control8
  5. CWE-416 Use After Free6
  6. CWE-79 XSS6

Latest CVEs

The 15 most recently published vulnerabilities in Hardware & Firmware.

  1. CVE-2026-18857This Power System update is being released to address3.4
  2. CVE-2026-76717Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)5.3
  3. CVE-2026-76716Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)5.3
  4. CVE-2026-76715Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.1
  5. CVE-2026-76714Authenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.2
  6. CVE-2026-76713Authenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.2
  7. CVE-2026-76712Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)7.3
  8. CVE-2026-76711Unauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.5
  9. CVE-2026-76710Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.5
  10. CVE-2026-76709Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE)9.8
  11. CVE-2026-76708Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)9.8
  12. CVE-2026-19915HP Support Assistant - Local Escalation of Privilege—
  13. CVE-2026-65112NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial ...6.5
  14. CVE-2026-65118NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to informati...7.5
  15. CVE-2026-65117NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tamperi...5.0

The record

Busiest month
Aug 2026, 371 CVEs
Sep 2026 so far
269 CVEs from 36 vendors
Deployment
Embedded, 78%
Monthly snapshots
250 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store