CVE Tools

ICS, OT & IoT

12,554 CVEs tracked since 2000. In the last 12 months, 2,359, +47% on the 12 before.

ICS, OT & IoT by subsector, Sep 2026 so far

Sep 2026 so far: 205 CVEs across 7 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • PLC, SCADA & HMI8441% · 13 vendors
  • Industrial networking5527% · 16 vendors
  • IP cameras & NVRs3015% · 4 vendors
  • Not yet sub-classified26The tagger has not placed these yet

Also: Smart home 8, Building automation 1, Medical devices 1.

Month by month

Every monthly snapshot of ICS, OT & IoT. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
ICS, OT & IoT CVEs per month
MonthCVEs
2021-0974
2021-1081
2021-1162
2021-12166
2022-01164
2022-02111
2022-03127
2022-04156
2022-0596
2022-06162
2022-07132
2022-08144
2022-09107
2022-1091
2022-11100
2022-12101
2023-01253
2023-02119
2023-030
2023-04100
2023-05154
2023-06142
2023-07178
2023-08189
2023-09102
2023-10155
2023-11148
2023-12100
2024-01161
2024-0294
2024-03108
2024-04110
2024-05219
2024-0690
2024-07117
2024-0893
2024-09104
2024-1095
2024-11181
2024-12100
2025-0198
2025-02102
2025-03113
2025-04101
2025-05180
2025-06149
2025-07259
2025-08126
2025-09172
2025-10204
2025-11158
2025-12310
2026-01241
2026-02207
2026-03176
2026-04128
2026-05226
2026-06209
2026-07196
2026-08132
2026-09205

Latest CVEs

The 15 most recently published vulnerabilities in ICS, OT & IoT.

  1. CVE-2026-93291Improper certificate validation in Eufy Omni C209.4
  2. CVE-2026-93290Use of Hard-coded Credentials in Eufy Omni C205.5
  3. CVE-2026-93289OS command injection in Eufy Omni C20, Omni X10 Pro7.5
  4. CVE-2026-56792Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabilit...4.4
  5. CVE-2026-81473Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabilit...8.1
  6. CVE-2026-13248Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface8.8
  7. CVE-2026-13249Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.0100409.8
  8. CVE-2026-77707TLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Liman Render Engine5.9
  9. CVE-2026-77703SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine5.9
  10. CVE-2026-19532Path Traversal in HAVELSAN's Liman MYS5.3
  11. CVE-2026-42801Deference after null check in as_rrc7.4
  12. CVE-2026-15027Changing|CGServiSign - OS Command Injection8.8
  13. CVE-2026-19438Mint Workbench I Path traversal Vulnerability7.5
  14. CVE-2026-88020Improper Neutralization of Input During Web Page Generation in OpenPLC Runtime v36.1
  15. CVE-2026-91129Home Assistant: mDNS Server-Side Request Forgery5.4

The record

Busiest month
Dec 2025, 310 CVEs
Sep 2026 so far
205 CVEs from 49 vendors
Deployment
On-prem, 77%
Monthly snapshots
233 since 2000
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store