February 2026
4,931 CVEs published, −6% on January 2026 and +25% on February 2025. CISA added 28 to KEV.
2026 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026 | January 2026: 5,244 CVEs17 added to CISA KEV | February 2026: 4,931 CVEs28 added to CISA KEV | March 2026: 6,821 CVEs26 added to CISA KEV | April 2026: 6,440 CVEs31 added to CISA KEV | May 2026: 7,365 CVEs21 added to CISA KEV | June 2026: 8,314 CVEs23 added to CISA KEV | July 2026: 10,240 CVEs26 added to CISA KEV | August 2026: 12,909 CVEs31 added to CISA KEV | September 2026 so far: 10,681 CVEs29 added to CISA KEV | 72,945+88%so far |
- Critical
- 49512% of the 4,283 with a CVSS score
- Added to CISA KEV
- 2819 of this month's CVEs are in KEV, listed a median 4 days after publication
- Vendors
- 2,0524,905 products
- Top weakness
- XSSCWE-79 · 678 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1npmOpenclaw, N8N, Fuxa-server22748nonenew
- 2LinuxLinux, Linux Kernel2201nonenew
- 3GoGogs.io/gogs, Github.com/mattermost/mattermost-server, Code.vikunja.io/api14320nonenew
- 4PyPIRucio-webui, Pypdf, Django12620nonenew
- 5PackagistCraftcms/cms, Moodle/moodle, Craftcms/commerce964nonenew
- 6MicrosoftWindows Server 2025, Windows Server 2025 (Server Core Installation), Windows Server 2022 23h27967new
- 7ApplemacOS, iOS and iPadOS, iPadOS7511new
- 8IBMConcert, DB2 Recovery Expert, DB2 Recovery Expert For Luw571nonenew
- 9MozillaFirefox, Thunderbird, Firefox For IOS5444nonenew
- 10TendaF453 Firmware, F453, A21 Firmware540nonenew
- 11Сообщество Свободного Программного ОбеспеченияN8N, Debian Gnu/linux, Vim528nonenew
- 12QnapQsync Central, File Station 5, File Station491nonenew
- 13D-LinkDwr-m960, Dir-823x, Dir-619l480nonenew
- 14DlinkDwr-m960 Firmware, Dir-823x Firmware, Dir-823x480nonenew
- 15Ооо «ред Софт»Ред Ос481nonenew
- 16Wikimedia FoundationMediawiki, Checkuser, Visualeditor471nonenew
- 17NugetMagick.net-q8-openmp-arm64, Magick.net-q8-anycpu, Magick.net-q16-openmp-x64461nonenew
- 18Red HatRed Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9461nonenew
- 19AdobeAfter Effects, Adobe After Effects, Substance3d - Designer440nonenew
- 20AmdAmd Epyc™ 9005 Series Processors, Amd Epyc™ Embedded 9005 Series Processors, Amd Ryzen™ Embedded 8000 Series Processors420nonenew
- 21Crates.ioRustfs, Wasmtime, Pgp401nonenew
- 22TaniumThreat Response, Tanos, Tanium Appliance400nonenew
- 23MavenOrg.keycloak:keycloak-services, Org.apache.tomcat:tomcat, Org.apache.tomcat.embed:tomcat-embed-core395nonenew
- 24ItsourcecodeSchool Management System, Event Management System, Student Management System370nonenew
- 25GoogleChrome, Google Chrome, Android3541new
Severity
How this month's CVEs score on CVSS; 648 have no score yet. Severity is not exploitation.
- Critical495
- High1,621
- Medium1,972
- Low195
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS678
- CWE-862Missing Authorization320
- CWE-89SQL Injection278
- CWE-22Path Traversal182
- CWE-78OS Command Injection158
- CWE-119Memory Buffer Bounds143
- CWE-74Injection134
- CWE-121130
- CWE-94Code Injection122
- CWE-787Out-of-bounds Write119
- CWE-284Improper Access Control110
- CWE-125Out-of-bounds Read99
- CWE-200Information Exposure99
- CWE-120Buffer Overflow98
- CWE-918SSRF96
- CWE-77Command Injection92
- CWE-502Deserialization82
- CWE-352CSRF81
- CWE-770Allocation Without Limits80
- CWE-416Use After Free79
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Web & CMS Plugins1,10719% of sector-tagged CVEs
- OSS Libraries1,01518% of sector-tagged CVEs
- Enterprise Software65811% of sector-tagged CVEs
- Operating Systems5039% of sector-tagged CVEs
- Networking Infrastructure3927% of sector-tagged CVEs
- Security Products2835% of sector-tagged CVEs
- Hardware Firmware2554% of sector-tagged CVEs
- Consumer Software2204% of sector-tagged CVEs
- 7 smaller sectors860
- Not yet classified432
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 862Missing Authorization | 89SQL Injection | 22Path Traversal | 78OS Command Injection | 119Memory Buffer Bounds | 74Injection | 121 | 94Code Injection | 787Out-of-bounds Write |
|---|---|---|---|---|---|---|---|---|---|---|
| npm | 23 | 5 | 4 | 14 | 16 | 9 | 17 | |||
| Linux | 2 | |||||||||
| Go | 9 | 10 | 1 | 20 | 6 | 1 | ||||
| PyPI | 14 | 2 | 6 | 10 | 1 | 2 | 1 | 7 | 1 | |
| Ооо «ред Софт» | 9 | 1 | 4 | 5 | 2 | 1 | 1 | 2 | 2 | 7 |
| Packagist | 37 | 3 | 15 | 2 | 1 | 4 | ||||
| Сообщество Свободного Программного Обеспечения | 11 | 2 | 2 | 10 | 4 | 1 | 1 | 3 | 1 | 8 |
| Apple | 1 | 8 | 12 | 2 | ||||||
| Microsoft Corp | 2 | 3 | 9 | |||||||
| Microsoft | 1 | 1 | 3 | 7 | ||||||
| Ооо «русбитех-астра» | 1 | 1 | 8 | |||||||
| IBM | 4 | 1 | 1 |
In the news
The CVEs security news mentioned most in February 2026.
- CVE-2025-20333A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remot...29.9
- CVE-2025-20362Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 a...26.5
- CVE-2026-21509Microsoft Office Security Feature Bypass Vulnerability27.8
- CVE-2021-34473Microsoft Exchange Server Remote Code Execution Vulnerability19.1
- CVE-2023-22527A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected vers...19.8
- CVE-2023-28771Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, ...19.8
- CVE-2023-41772Win32k Elevation of Privilege Vulnerability17.8
- CVE-2024-11182Stored XSS vulnerability in MDaemon Email Server16.1
- CVE-2024-27443An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, bec...16.1
- CVE-2024-28986SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability19.8
- CVE-2024-28988SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability19.8
- CVE-2024-30085Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability17.8