CVE Tools

Networking & Infrastructure

28,090 CVEs tracked since 1999. In the last 12 months, 4,995, +47% on the 12 before.

Networking & Infrastructure by subsector, Sep 2026 so far

Sep 2026 so far: 605 CVEs across 7 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • Not yet sub-classified339The tagger has not placed these yet
  • Routers & switches13522% · 20 vendors
  • Firewalls427% · 6 vendors
  • Load balancers & proxies356% · 13 vendors
  • Network management264% · 9 vendors

Also: VPN gateways 15, DNS, DHCP & NTP 13.

Month by month

Every monthly snapshot of Networking & Infrastructure. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Networking & Infrastructure CVEs per month
MonthCVEs
2021-09134
2021-10194
2021-1179
2021-12350
2022-0195
2022-02198
2022-03212
2022-04178
2022-05249
2022-06133
2022-07206
2022-08324
2022-09200
2022-10206
2022-11218
2022-12263
2023-01208
2023-02222
2023-030
2023-04282
2023-05181
2023-06143
2023-07148
2023-08286
2023-09201
2023-10311
2023-11207
2023-12210
2024-01297
2024-02153
2024-03299
2024-04337
2024-05511
2024-06134
2024-07286
2024-08249
2024-09255
2024-10313
2024-11332
2024-12107
2025-01337
2025-02203
2025-03256
2025-04234
2025-05388
2025-06328
2025-07325
2025-08318
2025-09236
2025-10330
2025-11177
2025-12278
2026-01313
2026-02392
2026-03521
2026-04585
2026-05791
2026-06383
2026-07441
2026-08548
2026-09605

Vendors

Who shipped the most Networking & Infrastructure CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Cisco97#13
  2. Aruba Networks52#18
  3. Arista Networks45#21
  4. OISF35#30
  5. Netcore32#33
  6. D-Link25#45
  7. ISC14#84
  8. Tenda14#88

Weaknesses

The weakness classes behind Networking & Infrastructure CVEs in Sep 2026 so far.

  1. CWE-79 XSS22
  2. CWE-269 Improper Privilege Mgmt20
  3. CWE-22 Path Traversal20
  4. CWE-284 Improper Access Control19
  5. CWE-89 SQL Injection19
  6. CWE-863 Incorrect Authorization17

Latest CVEs

The 15 most recently published vulnerabilities in Networking & Infrastructure.

  1. CVE-2026-100745Edimax BR-6428nC Wireless Wizard formWizSurvey stack-based overflow6.3
  2. CVE-2026-100740D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write9.9
  3. CVE-2026-100390Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv67.4
  4. CVE-2026-5267Unauthenticated Event Stream Exposure of Session Tokens in Navigator NCS7.5
  5. CVE-2026-27867CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC OF TELDAT—
  6. CVE-2026-97818phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.8.6
  7. CVE-2026-97730In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attac...8.5
  8. CVE-2026-85417Incomplete property masking in the SANnav logging subsystem—
  9. CVE-2026-14441Logic flaw in SANnav Java cache key handling object comparison handling—
  10. CVE-2026-14442Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a—
  11. CVE-2026-14443Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1a—
  12. CVE-2026-82372Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav before 3.0.1.a—
  13. CVE-2026-82371Plaintext exposure of sensitive authentication data in SANnav discovery service log files—
  14. CVE-2026-97362HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread7.5
  15. CVE-2026-97360HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine10.0

The record

Busiest month
May 2026, 791 CVEs
Sep 2026 so far
605 CVEs from 74 vendors
Deployment
On-prem, 64%
Monthly snapshots
297 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store