March 2026
6,821 CVEs published, +38% on February 2026 and +60% on March 2025. CISA added 26 to KEV.
2026 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026 | January 2026: 5,244 CVEs17 added to CISA KEV | February 2026: 4,931 CVEs28 added to CISA KEV | March 2026: 6,821 CVEs26 added to CISA KEV | April 2026: 6,440 CVEs31 added to CISA KEV | May 2026: 7,365 CVEs21 added to CISA KEV | June 2026: 8,314 CVEs23 added to CISA KEV | July 2026: 10,240 CVEs26 added to CISA KEV | August 2026: 12,909 CVEs31 added to CISA KEV | September 2026 so far: 10,681 CVEs29 added to CISA KEV | 72,945+88%so far |
- Critical
- 68511% of the 6,046 with a CVSS score
- Added to CISA KEV
- 268 of this month's CVEs are in KEV, listed a median 3 days after publication
- Vendors
- 2,2815,659 products
- Top weakness
- XSSCWE-79 · 765 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1npmOpenclaw, Parse-server, Nocodb56229nonenew
- 2OpenclawOpenclaw, Voice-call, Nextcloud-talk19917nonenew
- 3GoogleAndroid, Chrome, Google Chrome178122new
- 4LinuxLinux, Linux Kernel1781nonenew
- 5Сообщество Свободного Программного ОбеспеченияDebian Gnu/linux, Openclaw, Linux145102new
- 6MicrosoftMicrosoft Edge, Windows 10 Version 21h2, Windows 10 Version 22h214472new
- 7GoGithub.com/siyuan-note/siyuan/kernel, Github.com/olivetin/olivetin, Github.com/forceu/gokapi13919nonenew
- 8ThemerexAldo, Alliance, Aqualots10513nonenew
- 9PyPIGlances, Openssl-encrypt, Justhtml946nonenew
- 10ApplemacOS, iOS and iPadOS, iPadOS893nonenew
- 11Red HatRed Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux891nonenew
- 12PackagistCraftcms/cms, Wwbn/avideo, Admidio/admidio888nonenew
- 13TendaF453, F453 Firmware, W20E Firmware8814nonenew
- 14WwbnAvideo, Avideo-encoder8411nonenew
- 15AdobeAdobe Experience Manager, Experience Manager, Magento Open Source820nonenew
- 16IBMInfosphere Information Server, Sterling File Gateway, Sterling B2B Integrator720nonenew
- 17CiscoCisco Secure Firewall Threat Defense (FTD) Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Adaptive Security Appliance Software7021new
- 18DlinkDir-513 Firmware, Dns-726-4 Firmware, Dns-320l Firmware6626nonenew
- 19Parse-communityParse-server6510nonenew
- 20SourcecodesterSales and Inventory System, Client Database Management System, Resort Reservation System600nonenew
- 21code-projectsSimple Flight Ticket Booking System, Exam Form Submission, Simple Laundry System550nonenew
- 22MozillaFirefox, Thunderbird, Firefox Esr5121nonenew
- 23Crates.ioZeptoclaw, Aws-lc-sys, Vaultwarden501nonenew
- 24DiscourseDiscourse480nonenew
- 25LinuxfoundationEverest, Nats-server, Backstage453nonenew
Severity
How this month's CVEs score on CVSS; 775 have no score yet. Severity is not exploitation.
- Critical685
- High2,518
- Medium2,578
- Low265
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS765
- CWE-89SQL Injection478
- CWE-862Missing Authorization353
- CWE-787Out-of-bounds Write292
- CWE-22Path Traversal271
- CWE-863Incorrect Authorization265
- CWE-74Injection229
- CWE-98223
- CWE-94Code Injection201
- CWE-78OS Command Injection187
- CWE-918SSRF185
- CWE-121178
- CWE-284Improper Access Control163
- CWE-119Memory Buffer Bounds159
- CWE-125Out-of-bounds Read152
- CWE-639Auth Bypass via User Key136
- CWE-200Information Exposure129
- CWE-502Deserialization119
- CWE-20Improper Input Validation118
- CWE-306Missing Auth for Critical Function117
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- OSS Libraries1,60020% of sector-tagged CVEs
- Web & CMS Plugins1,58120% of sector-tagged CVEs
- Enterprise Software86311% of sector-tagged CVEs
- Operating Systems5988% of sector-tagged CVEs
- Networking Infrastructure5217% of sector-tagged CVEs
- Security Products4496% of sector-tagged CVEs
- Mobile Apps3194% of sector-tagged CVEs
- Consumer Software3054% of sector-tagged CVEs
- 7 smaller sectors1,120
- Not yet classified508
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 89SQL Injection | 862Missing Authorization | 787Out-of-bounds Write | 22Path Traversal | 863Incorrect Authorization | 74Injection | 98 | 94Code Injection | 78OS Command Injection |
|---|---|---|---|---|---|---|---|---|---|---|
| npm | 32 | 6 | 18 | 41 | 104 | 6 | 6 | 35 | ||
| Сообщество Свободного Программного Обеспечения | 9 | 2 | 3 | 12 | 12 | 8 | 3 | 17 | ||
| Ооо «ред Софт» | 4 | 5 | 17 | 10 | 2 | 1 | 2 | 3 | ||
| Openclaw | 1 | 1 | 20 | 37 | 1 | 2 | 17 | |||
| Linux | 8 | |||||||||
| 1 | 5 | 37 | 3 | 1 | 1 | |||||
| Go | 14 | 3 | 6 | 13 | 13 | 2 | 1 | 1 | ||
| Microsoft Corp | 2 | 1 | 8 | 1 | 1 | 1 | ||||
| Red Hat Inc. | 2 | 8 | 6 | |||||||
| Themerex | 93 | |||||||||
| Microsoft | 2 | 1 | 2 | 1 | 1 | |||||
| PyPI | 10 | 3 | 3 | 8 | 3 | 1 | 2 | 1 |
In the news
The CVEs security news mentioned most in March 2026.
- CVE-2025-14174Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security sev...28.8
- CVE-2025-5777NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread27.5
- CVE-2025-61882Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploita...29.8
- CVE-2025-8088Path traversal vulnerability in WinRAR28.8
- CVE-2026-3055Insufficient input validation leading to memory overread29.8
- CVE-2005-0469Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large numb...17.5
- CVE-2019-6693Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledg...16.5
- CVE-2020-27932A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Securit...17.8
- CVE-2020-27950A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Moja...15.5
- CVE-2021-27877An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current ...18.2
- CVE-2021-27878An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS commun...18.8
- CVE-2021-30952An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously c...17.8