ICS, OT & IoT
12,554 CVEs tracked since 2000. In the last 12 months, 2,359, +47% on the 12 before.
ICS, OT & IoT by subsector, Sep 2026 so far
- PLC, SCADA & HMI8441% · 13 vendors
- Industrial networking5527% · 16 vendors
- IP cameras & NVRs3015% · 4 vendors
- Not yet sub-classified26The tagger has not placed these yet
Also: Smart home 8, Building automation 1, Medical devices 1.
Month by month
Every monthly snapshot of ICS, OT & IoT. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 74 |
| 2021-10 | 81 |
| 2021-11 | 62 |
| 2021-12 | 166 |
| 2022-01 | 164 |
| 2022-02 | 111 |
| 2022-03 | 127 |
| 2022-04 | 156 |
| 2022-05 | 96 |
| 2022-06 | 162 |
| 2022-07 | 132 |
| 2022-08 | 144 |
| 2022-09 | 107 |
| 2022-10 | 91 |
| 2022-11 | 100 |
| 2022-12 | 101 |
| 2023-01 | 253 |
| 2023-02 | 119 |
| 2023-03 | 0 |
| 2023-04 | 100 |
| 2023-05 | 154 |
| 2023-06 | 142 |
| 2023-07 | 178 |
| 2023-08 | 189 |
| 2023-09 | 102 |
| 2023-10 | 155 |
| 2023-11 | 148 |
| 2023-12 | 100 |
| 2024-01 | 161 |
| 2024-02 | 94 |
| 2024-03 | 108 |
| 2024-04 | 110 |
| 2024-05 | 219 |
| 2024-06 | 90 |
| 2024-07 | 117 |
| 2024-08 | 93 |
| 2024-09 | 104 |
| 2024-10 | 95 |
| 2024-11 | 181 |
| 2024-12 | 100 |
| 2025-01 | 98 |
| 2025-02 | 102 |
| 2025-03 | 113 |
| 2025-04 | 101 |
| 2025-05 | 180 |
| 2025-06 | 149 |
| 2025-07 | 259 |
| 2025-08 | 126 |
| 2025-09 | 172 |
| 2025-10 | 204 |
| 2025-11 | 158 |
| 2025-12 | 310 |
| 2026-01 | 241 |
| 2026-02 | 207 |
| 2026-03 | 176 |
| 2026-04 | 128 |
| 2026-05 | 226 |
| 2026-06 | 209 |
| 2026-07 | 196 |
| 2026-08 | 132 |
| 2026-09 | 205 |
Vendors
Who shipped the most ICS, OT & IoT CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind ICS, OT & IoT CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in ICS, OT & IoT.
- CVE-2026-93291Improper certificate validation in Eufy Omni C209.4
- CVE-2026-93290Use of Hard-coded Credentials in Eufy Omni C205.5
- CVE-2026-93289OS command injection in Eufy Omni C20, Omni X10 Pro7.5
- CVE-2026-56792Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabilit...4.4
- CVE-2026-81473Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabilit...8.1
- CVE-2026-13248Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface8.8
- CVE-2026-13249Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.0100409.8
- CVE-2026-77707TLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Liman Render Engine5.9
- CVE-2026-77703SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine5.9
- CVE-2026-19532Path Traversal in HAVELSAN's Liman MYS5.3
- CVE-2026-42801Deference after null check in as_rrc7.4
- CVE-2026-15027Changing|CGServiSign - OS Command Injection8.8
- CVE-2026-19438Mint Workbench I Path traversal Vulnerability7.5
- CVE-2026-88020Improper Neutralization of Input During Web Page Generation in OpenPLC Runtime v36.1
- CVE-2026-91129Home Assistant: mDNS Server-Side Request Forgery5.4
The record
- Busiest month
- Dec 2025, 310 CVEs
- Sep 2026 so far
- 205 CVEs from 49 vendors
- Deployment
- On-prem, 77%
- Monthly snapshots
- 233 since 2000
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment