January 2026
5,244 CVEs published, −9% on December 2025 and +17% on January 2025. CISA added 17 to KEV.
2026 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026 | January 2026: 5,244 CVEs17 added to CISA KEV | February 2026: 4,931 CVEs28 added to CISA KEV | March 2026: 6,821 CVEs26 added to CISA KEV | April 2026: 6,440 CVEs31 added to CISA KEV | May 2026: 7,365 CVEs21 added to CISA KEV | June 2026: 8,314 CVEs23 added to CISA KEV | July 2026: 10,240 CVEs26 added to CISA KEV | August 2026: 12,909 CVEs31 added to CISA KEV | September 2026 so far: 10,681 CVEs29 added to CISA KEV | 72,945+88%so far |
- Critical
- 43711% of the 4,087 with a CVSS score
- Added to CISA KEV
- 1713 of this month's CVEs are in KEV, listed a median 5 days after publication
- Vendors
- 2,1525,678 products
- Top weakness
- XSSCWE-79 · 627 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1LinuxLinux, Linux Kernel2461nonenew
- 2Сообщество Свободного Программного ОбеспеченияLinux, Debian Gnu/linux, Gpac20614nonenew
- 3npmPnpm, Hono, Renovate14220nonenew
- 4MicrosoftWindows 11 25h2, Windows Server 2025, Windows 11 24h213453new
- 5Ао «ивк»Альт Сп 10, Альт 8 Сп11816nonenew
- 6Red HatRed Hat Enterprise Linux, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 101114nonenew
- 7PyPIAiohttp, Fickling, Vllm986nonenew
- 8GoGithub.com/go-gitea/gitea, Github.com/siyuan-note/siyuan/kernel, Github.com/axllent/mailpit8511nonenew
- 9CanonicalUbuntu, Juju772nonenew
- 10OracleVm VirtualBox, Oracle Vm VirtualBox, MySQL Server662nonenew
- 11Ооо «ред Софт»Ред Ос664nonenew
- 12ColorIccdev591nonenew
- 13InternationalcolorconsortiumIccdev591nonenew
- 14PackagistBagisto/bagisto, Craftcms/cms, Mineadmin/mineadmin586nonenew
- 15MavenNet.gleske:jervis, Org.keycloak:keycloak-services, Org.apache.solr:solr-core536nonenew
- 16Ао «сбертех»Platform V Sberlinux OS Server510nonenew
- 17TendaAX1806 Firmware, W30E Firmware, AX3 Firmware496nonenew
- 18GoogleAndroid, Chrome, Google Chrome453nonenew
- 19code-projectsOnline Product Reservation System, Online Music Site, Intern Membership Management System440nonenew
- 20Shenzhen Tenda Technology Co., Ltd.W30E V2, Tenda W30E, Tenda AX1806423nonenew
- 21IBMDB2 For Linux, Unix and Windows, DB2, Applinx390nonenew
- 22QnapQuts Hero, Qts, Hybrid Backup Sync352nonenew
- 23Crates.ioRustfs, SM2, Gix-date324nonenew
- 24FabianOnline Product Reservation System, Online Music Site, Mobile Shop Management System324nonenew
- 25MeddreamPacs Server, Meddream Pacs Premium, Meddream Pacs Server301nonenew
Severity
How this month's CVEs score on CVSS; 1,157 have no score yet. Severity is not exploitation.
- Critical437
- High1,659
- Medium1,851
- Low140
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS627
- CWE-862Missing Authorization309
- CWE-89SQL Injection242
- CWE-74Injection129
- CWE-20Improper Input Validation124
- CWE-22Path Traversal123
- CWE-787Out-of-bounds Write119
- CWE-428110
- CWE-284Improper Access Control104
- CWE-352CSRF102
- CWE-434Unrestricted File Upload102
- CWE-78OS Command Injection101
- CWE-94Code Injection96
- CWE-9893
- CWE-77Command Injection87
- CWE-476NULL Pointer Dereference85
- CWE-416Use After Free83
- CWE-120Buffer Overflow82
- CWE-200Information Exposure82
- CWE-770Allocation Without Limits81
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Web & CMS Plugins1,11521% of sector-tagged CVEs
- OSS Libraries84216% of sector-tagged CVEs
- Operating Systems63612% of sector-tagged CVEs
- Enterprise Software4949% of sector-tagged CVEs
- Networking Infrastructure3136% of sector-tagged CVEs
- ICS / OT / IoT2415% of sector-tagged CVEs
- Hardware Firmware2354% of sector-tagged CVEs
- 8 smaller sectors908
- Not yet classified487
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 862Missing Authorization | 89SQL Injection | 74Injection | 20Improper Input Validation | 22Path Traversal | 787Out-of-bounds Write | 428 | 284Improper Access Control | 352CSRF |
|---|---|---|---|---|---|---|---|---|---|---|
| Linux | 3 | |||||||||
| Сообщество Свободного Программного Обеспечения | 3 | 4 | 9 | 5 | 2 | 1 | ||||
| Ао «ивк» | 1 | 7 | ||||||||
| npm | 19 | 3 | 2 | 6 | 11 | 1 | 4 | 2 | ||
| Microsoft | 2 | 1 | 3 | 1 | 8 | |||||
| Microsoft Corp | 5 | 1 | 3 | 8 | ||||||
| Ооо «ред Софт» | 1 | 1 | 1 | 1 | 1 | 5 | 12 | 3 | 1 | |
| Red Hat Inc. | 2 | 1 | 5 | |||||||
| PyPI | 7 | 3 | 1 | 1 | 10 | 1 | 3 | 2 | ||
| Canonical Ltd. | 1 | 1 | 1 | |||||||
| Ооо «русбитех-астра» | 1 | 1 | 1 | 10 | 1 | 1 | ||||
| Go | 6 | 3 | 1 | 3 | 10 | 10 |
In the news
The CVEs security news mentioned most in January 2026.
- CVE-2025-36934In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional ...27.4
- CVE-2025-52691Upload Arbitrary Files210.0
- CVE-2025-54957An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+ bitstream is processed. When Evolution data is processed by evo_priv.c from ...29.8
- CVE-2017-0199Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote...17.8
- CVE-2017-11882Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of...17.8
- CVE-2025-12420Unauthenticated Privilege Escalation in ServiceNow AI Platform19.8
- CVE-2025-14847Zlib compressed protocol header length confusion may allow memory read17.5
- CVE-2025-49415WordPress FW Gallery plugin <= 8.0.0 - Arbitrary File Deletion Vulnerability18.6
- CVE-2025-55182A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, rea...110.0
- CVE-2025-62221Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability17.8
- CVE-2025-66478Untitled vulnerability1—
- CVE-2025-67968WordPress Real Homes CRM plugin <= 1.0.0 - Arbitrary File Upload vulnerability19.9