April 2026
6,440 CVEs published, −6% on March 2026 and +50% on April 2025. CISA added 31 to KEV.
2026 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026 | January 2026: 5,244 CVEs17 added to CISA KEV | February 2026: 4,931 CVEs28 added to CISA KEV | March 2026: 6,821 CVEs26 added to CISA KEV | April 2026: 6,440 CVEs31 added to CISA KEV | May 2026: 7,365 CVEs21 added to CISA KEV | June 2026: 8,314 CVEs23 added to CISA KEV | July 2026: 10,240 CVEs26 added to CISA KEV | August 2026: 12,909 CVEs31 added to CISA KEV | September 2026 so far: 10,681 CVEs29 added to CISA KEV | 72,945+88%so far |
- Critical
- 60711% of the 5,693 with a CVSS score
- Added to CISA KEV
- 3110 of this month's CVEs are in KEV, listed a median 5 days after publication
- Vendors
- 1,9714,836 products
- Top weakness
- XSSCWE-79 · 620 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1LinuxLinux, Linux Kernel379291new
- 2npmOpenclaw, Flowise, Flowise-components3090nonenew
- 3MicrosoftWindows Server 2025 (Server Core Installation), Windows Server 2025, Windows Server 2022, 23h2 Edition (Server Core Installation)185153new
- 4OpenclawOpenclaw1742nonenew
- 5GoogleChrome, Google Chrome, Android14791new
- 6OracleMySQL Server, Jdk, Oracle Java Se1025nonenew
- 7TotolinkA7100RU, A8000RU, A3300R Firmware9463nonenew
- 8code-projectsSimple Laundry System, Vehicle Showroom Management System, Simple It Discussion Forum910nonenew
- 9TendaF456, F456 Firmware, F451876nonenew
- 10Apache Software FoundationApache Airflow, Apache Tomcat, Apache Thrift86111new
- 11ApacheAirflow, Tomcat, Camel84111new
- 12Red HatRed Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 77331new
- 13GoGithub.com/lin-snow/ech0, Github.com/patrickhener/goshs/v2, Github.com/kyverno/kyverno620nonenew
- 14PyPIPraisonai, Praisonaiagents, Openssl-encrypt590nonenew
- 15AdobeFramemaker, Adobe Framemaker, Adobe Indesign5771new
- 16PackagistWwbn/avideo, Froxlor/froxlor, Pocketmine/pocketmine-mp570nonenew
- 17SourcecodesterPizzafy Ecommerce System, Pharmacy Sales and Inventory System, Record Management System540nonenew
- 18DlinkDi-8003 Firmware, Di-8003, Dir-605l Firmware521nonenew
- 19MozillaFirefox, Thunderbird, Firefox Esr528nonenew
- 20IBMVerify Identity Access, Verify Identity Access Container, Security Verify Access Container481nonenew
- 21DellData Domain Operating System, Powerprotect Data Domain, Powerprotect Dp Series Appliance450nonenew
- 22PraisonPraisonai, Praisonaiagents4414nonenew
- 23UutilsCoreutils440nonenew
- 24WiresharkWireshark420nonenew
- 25Wireshark FoundationWireshark420nonenew
Severity
How this month's CVEs score on CVSS; 747 have no score yet. Severity is not exploitation.
- Critical607
- High2,243
- Medium2,568
- Low275
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS620
- CWE-89SQL Injection391
- CWE-22Path Traversal292
- CWE-862Missing Authorization282
- CWE-78OS Command Injection236
- CWE-918SSRF235
- CWE-416Use After Free215
- CWE-74Injection210
- CWE-94Code Injection206
- CWE-77Command Injection189
- CWE-284Improper Access Control188
- CWE-863Incorrect Authorization157
- CWE-120Buffer Overflow143
- CWE-119Memory Buffer Bounds140
- CWE-125Out-of-bounds Read140
- CWE-787Out-of-bounds Write140
- CWE-200Information Exposure130
- CWE-639Auth Bypass via User Key128
- CWE-20Improper Input Validation122
- CWE-306Missing Auth for Critical Function114
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- OSS Libraries1,12017% of sector-tagged CVEs
- Web & CMS Plugins1,02516% of sector-tagged CVEs
- Operating Systems76112% of sector-tagged CVEs
- Enterprise Software67610% of sector-tagged CVEs
- Networking Infrastructure5859% of sector-tagged CVEs
- Security Products4236% of sector-tagged CVEs
- AI / ML2494% of sector-tagged CVEs
- 8 smaller sectors1,295
- Not yet classified396
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 89SQL Injection | 22Path Traversal | 862Missing Authorization | 78OS Command Injection | 918SSRF | 416Use After Free | 74Injection | 94Code Injection | 77Command Injection |
|---|---|---|---|---|---|---|---|---|---|---|
| Linux | 57 | |||||||||
| npm | 8 | 3 | 21 | 20 | 10 | 25 | 2 | 6 | 4 | |
| Microsoft | 2 | 2 | 1 | 6 | 55 | 1 | 2 | |||
| Microsoft Corp | 2 | 2 | 1 | 3 | 56 | 2 | ||||
| Openclaw | 6 | 11 | 8 | |||||||
| Сообщество Свободного Программного Обеспечения | 4 | 2 | 8 | 1 | 6 | 3 | 19 | 3 | ||
| 57 | ||||||||||
| Google Inc | 56 | |||||||||
| Ооо «ред Софт» | 4 | 2 | 6 | 2 | 1 | 16 | 2 | |||
| Oracle | ||||||||||
| Oracle Corporation | ||||||||||
| Totolink | 69 | 84 |
In the news
The CVEs security news mentioned most in April 2026.
- CVE-2026-33825Microsoft Defender Elevation of Privilege Vulnerability27.8
- CVE-2019-15126An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper ...13.1
- CVE-2022-1026Kyocera Net View Address Book Exposure18.6
- CVE-2023-1389TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web mana...18.8
- CVE-2023-35317Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability17.8
- CVE-2023-50224TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability16.5
- CVE-2024-50623In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.19.8
- CVE-2025-10035Deserialization Vulnerability in GoAnywhere MFT's License Servlet110.0
- CVE-2025-29635A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibi...17.2
- CVE-2025-49704Microsoft SharePoint Remote Code Execution Vulnerability18.8
- CVE-2025-55182A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, rea...110.0
- CVE-2025-59287Windows Server Update Service (WSUS) Remote Code Execution Vulnerability19.8