Hardware & Firmware
14,893 CVEs tracked since 1999. In the last 12 months, 2,446, +19% on the 12 before.
Hardware & Firmware by subsector, Sep 2026 so far
- Network adapters10138% · 8 vendors
- Not yet sub-classified79The tagger has not placed these yet
- CPUs & GPUs5621% · 8 vendors
- BIOS & UEFI166% · 6 vendors
- Storage & NAS145% · 2 vendors
- Printers & peripherals31% · 1 vendor
Month by month
Every monthly snapshot of Hardware & Firmware. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 90 |
| 2021-10 | 71 |
| 2021-11 | 154 |
| 2021-12 | 27 |
| 2022-01 | 166 |
| 2022-02 | 165 |
| 2022-03 | 60 |
| 2022-04 | 113 |
| 2022-05 | 176 |
| 2022-06 | 147 |
| 2022-07 | 84 |
| 2022-08 | 143 |
| 2022-09 | 137 |
| 2022-10 | 109 |
| 2022-11 | 190 |
| 2022-12 | 162 |
| 2023-01 | 258 |
| 2023-02 | 319 |
| 2023-03 | 0 |
| 2023-04 | 180 |
| 2023-05 | 327 |
| 2023-06 | 170 |
| 2023-07 | 195 |
| 2023-08 | 264 |
| 2023-09 | 192 |
| 2023-10 | 152 |
| 2023-11 | 312 |
| 2023-12 | 219 |
| 2024-01 | 208 |
| 2024-02 | 248 |
| 2024-03 | 148 |
| 2024-04 | 150 |
| 2024-05 | 174 |
| 2024-06 | 119 |
| 2024-07 | 113 |
| 2024-08 | 182 |
| 2024-09 | 144 |
| 2024-10 | 118 |
| 2024-11 | 243 |
| 2024-12 | 143 |
| 2025-01 | 127 |
| 2025-02 | 211 |
| 2025-03 | 160 |
| 2025-04 | 123 |
| 2025-05 | 167 |
| 2025-06 | 212 |
| 2025-07 | 166 |
| 2025-08 | 240 |
| 2025-09 | 173 |
| 2025-10 | 187 |
| 2025-11 | 205 |
| 2025-12 | 194 |
| 2026-01 | 235 |
| 2026-02 | 255 |
| 2026-03 | 174 |
| 2026-04 | 96 |
| 2026-05 | 215 |
| 2026-06 | 186 |
| 2026-07 | 155 |
| 2026-08 | 371 |
| 2026-09 | 269 |
Vendors
Who shipped the most Hardware & Firmware CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Hardware & Firmware CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Hardware & Firmware.
- CVE-2026-18857This Power System update is being released to address3.4
- CVE-2026-76717Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)5.3
- CVE-2026-76716Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)5.3
- CVE-2026-76715Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.1
- CVE-2026-76714Authenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.2
- CVE-2026-76713Authenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.2
- CVE-2026-76712Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)7.3
- CVE-2026-76711Unauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.5
- CVE-2026-76710Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)7.5
- CVE-2026-76709Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE)9.8
- CVE-2026-76708Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)9.8
- CVE-2026-19915HP Support Assistant - Local Escalation of Privilege—
- CVE-2026-65112NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial ...6.5
- CVE-2026-65118NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to informati...7.5
- CVE-2026-65117NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tamperi...5.0
The record
- Busiest month
- Aug 2026, 371 CVEs
- Sep 2026 so far
- 269 CVEs from 36 vendors
- Deployment
- Embedded, 78%
- Monthly snapshots
- 250 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment