Networking & Infrastructure
28,090 CVEs tracked since 1999. In the last 12 months, 4,995, +47% on the 12 before.
Networking & Infrastructure by subsector, Sep 2026 so far
- Not yet sub-classified339The tagger has not placed these yet
- Routers & switches13522% · 20 vendors
- Firewalls427% · 6 vendors
- Load balancers & proxies356% · 13 vendors
- Network management264% · 9 vendors
Also: VPN gateways 15, DNS, DHCP & NTP 13.
Month by month
Every monthly snapshot of Networking & Infrastructure. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 134 |
| 2021-10 | 194 |
| 2021-11 | 79 |
| 2021-12 | 350 |
| 2022-01 | 95 |
| 2022-02 | 198 |
| 2022-03 | 212 |
| 2022-04 | 178 |
| 2022-05 | 249 |
| 2022-06 | 133 |
| 2022-07 | 206 |
| 2022-08 | 324 |
| 2022-09 | 200 |
| 2022-10 | 206 |
| 2022-11 | 218 |
| 2022-12 | 263 |
| 2023-01 | 208 |
| 2023-02 | 222 |
| 2023-03 | 0 |
| 2023-04 | 282 |
| 2023-05 | 181 |
| 2023-06 | 143 |
| 2023-07 | 148 |
| 2023-08 | 286 |
| 2023-09 | 201 |
| 2023-10 | 311 |
| 2023-11 | 207 |
| 2023-12 | 210 |
| 2024-01 | 297 |
| 2024-02 | 153 |
| 2024-03 | 299 |
| 2024-04 | 337 |
| 2024-05 | 511 |
| 2024-06 | 134 |
| 2024-07 | 286 |
| 2024-08 | 249 |
| 2024-09 | 255 |
| 2024-10 | 313 |
| 2024-11 | 332 |
| 2024-12 | 107 |
| 2025-01 | 337 |
| 2025-02 | 203 |
| 2025-03 | 256 |
| 2025-04 | 234 |
| 2025-05 | 388 |
| 2025-06 | 328 |
| 2025-07 | 325 |
| 2025-08 | 318 |
| 2025-09 | 236 |
| 2025-10 | 330 |
| 2025-11 | 177 |
| 2025-12 | 278 |
| 2026-01 | 313 |
| 2026-02 | 392 |
| 2026-03 | 521 |
| 2026-04 | 585 |
| 2026-05 | 791 |
| 2026-06 | 383 |
| 2026-07 | 441 |
| 2026-08 | 548 |
| 2026-09 | 605 |
Vendors
Who shipped the most Networking & Infrastructure CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Networking & Infrastructure CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Networking & Infrastructure.
- CVE-2026-100745Edimax BR-6428nC Wireless Wizard formWizSurvey stack-based overflow6.3
- CVE-2026-100740D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write9.9
- CVE-2026-100390Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv67.4
- CVE-2026-5267Unauthenticated Event Stream Exposure of Session Tokens in Navigator NCS7.5
- CVE-2026-27867CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC OF TELDAT—
- CVE-2026-97818phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.8.6
- CVE-2026-97730In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attac...8.5
- CVE-2026-85417Incomplete property masking in the SANnav logging subsystem—
- CVE-2026-14441Logic flaw in SANnav Java cache key handling object comparison handling—
- CVE-2026-14442Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a—
- CVE-2026-14443Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1a—
- CVE-2026-82372Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav before 3.0.1.a—
- CVE-2026-82371Plaintext exposure of sensitive authentication data in SANnav discovery service log files—
- CVE-2026-97362HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread7.5
- CVE-2026-97360HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine10.0
The record
- Busiest month
- May 2026, 791 CVEs
- Sep 2026 so far
- 605 CVEs from 74 vendors
- Deployment
- On-prem, 64%
- Monthly snapshots
- 297 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment