May 2026
7,365 CVEs published, +14% on April 2026 and +69% on May 2025. CISA added 21 to KEV.
2026 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026 | January 2026: 5,244 CVEs17 added to CISA KEV | February 2026: 4,931 CVEs28 added to CISA KEV | March 2026: 6,821 CVEs26 added to CISA KEV | April 2026: 6,440 CVEs31 added to CISA KEV | May 2026: 7,365 CVEs21 added to CISA KEV | June 2026: 8,314 CVEs23 added to CISA KEV | July 2026: 10,240 CVEs26 added to CISA KEV | August 2026: 12,909 CVEs31 added to CISA KEV | September 2026 so far: 10,681 CVEs29 added to CISA KEV | 72,945+88%so far |
- Critical
- 64210% of the 6,642 with a CVSS score
- Added to CISA KEV
- 2119 of this month's CVEs are in KEV, listed a median 2 days after publication
- Vendors
- 2,0465,828 products
- Top weakness
- XSSCWE-79 · 601 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1LinuxLinux, Linux Kernel1,02843none—
- 2GoogleChrome, Google Chrome, Android38013none+3
- 3MicrosoftMicrosoft Edge, Windows Server 2025 (Server Core Installation), Windows Server 2025278263—
- 4Сообщество Свободного Программного ОбеспеченияDebian Gnu/linux, Open Webui, Linux266252+25
- 5ApplemacOS, iPadOS, iPhone OS1000none+57
- 6Red HatRed Hat Enterprise Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9956none+6
- 7Apache Software FoundationApache Ofbiz, HTTP Server, Apache HTTP Server8719none+3
- 8npmOpenclaw, Flowise, @hulumi/policies860none−6
- 9Ооо «русбитех-астра»Astra Linux Special Edition, Parsec, Linux Astra Modules840nonenew
- 10ApacheOfbiz, HTTP Server, Cloudstack8018none+1
- 11OpenclawOpenclaw, Crabbox758none−7
- 12EdimaxEw-7438rpn, Br-6675nd, Br-6478ac590nonenew
- 13Open-webuiOpen-webui591nonenew
- 14OpenwebuiOpen Webui591nonenew
- 15Ао «ивк»Альт Сп 10, Альт 8 Сп573nonenew
- 16F5BIG-IP, BIG-IP SSL Orchestrator, BIG-IP Application Security Manager531nonenew
- 17AdobeCommerce B2B, Magento Open Source, Adobe Commerce522none−2
- 18TotolinkA8000RU, CA750-POE, N300RH5031none−11
- 19AmdAmd Ryzen™ Embedded 8000 Series Processors, Amd Ryzen™ 7035 Series Processors With Radeon™ Graphics (Formerly Codenamed "rembrandt R"), Amd Ryzen™ 8040 Series Mobile Processors With Radeon™ Graphics (Formerly Codenamed "hawk Point")490nonenew
- 20IBMHTTP Server, DB2, Aspera High-speed Transfer Server496none—
- 21Edimax Technology Co., Ltd.Edimax Ew-7438rpn, Edimax Br-6675nd, Edimax Br-6478ac460nonenew
- 22Concrete CMSConcrete CMS440nonenew
- 23Crates.ioGix, Diesel, Lemmy_api440none+29
- 24MozillaFirefox, Thunderbird, Firefox Esr449none−5
- 25Open IsesTickets, Open Ises Project440nonenew
Severity
How this month's CVEs score on CVSS; 723 have no score yet. Severity is not exploitation.
- Critical642
- High2,735
- Medium2,992
- Low273
Breakouts
Vendors with at least three times their own 12-month median.
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS601
- CWE-89SQL Injection382
- CWE-862Missing Authorization311
- CWE-416Use After Free305
- CWE-22Path Traversal236
- CWE-78OS Command Injection219
- CWE-476NULL Pointer Dereference208
- CWE-125Out-of-bounds Read202
- CWE-94Code Injection199
- CWE-20Improper Input Validation195
- CWE-77Command Injection187
- CWE-918SSRF187
- CWE-284Improper Access Control177
- CWE-74Injection166
- CWE-119Memory Buffer Bounds165
- CWE-787Out-of-bounds Write160
- CWE-863Incorrect Authorization160
- CWE-639Auth Bypass via User Key137
- CWE-352CSRF135
- CWE-121129
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Operating Systems2,69329% of sector-tagged CVEs
- OSS Libraries1,17513% of sector-tagged CVEs
- Web & CMS Plugins1,13412% of sector-tagged CVEs
- Networking Infrastructure7918% of sector-tagged CVEs
- Consumer Software7298% of sector-tagged CVEs
- Enterprise Software5916% of sector-tagged CVEs
- Cloud & SaaS4004% of sector-tagged CVEs
- 8 smaller sectors1,608
- Not yet classified223
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 89SQL Injection | 862Missing Authorization | 416Use After Free | 22Path Traversal | 78OS Command Injection | 476NULL Pointer Dereference | 125Out-of-bounds Read | 94Code Injection | 20Improper Input Validation |
|---|---|---|---|---|---|---|---|---|---|---|
| Linux | 96 | 115 | 63 | |||||||
| 4 | 1 | 129 | 31 | 4 | 55 | |||||
| Сообщество Свободного Программного Обеспечения | 12 | 7 | 11 | 26 | 2 | 6 | 14 | 14 | 5 | 15 |
| Microsoft Corp | 7 | 1 | 50 | 2 | 1 | 6 | 12 | 3 | 33 | |
| Microsoft | 5 | 2 | 28 | 5 | 2 | 6 | 4 | 3 | 7 | |
| Google Inc | 3 | 33 | 9 | 1 | 31 | |||||
| Apple | 1 | 7 | 2 | 1 | 5 | 5 | ||||
| Apache Software Foundation | 4 | 2 | 4 | 2 | 2 | 6 | 7 | |||
| npm | 3 | 5 | 3 | 2 | 2 | |||||
| Apache | 4 | 2 | 4 | 2 | 2 | 6 | 7 | |||
| Ооо «русбитех-астра» | 8 | 18 | 13 | 6 | ||||||
| Openclaw | 16 | 2 | 1 |
In the news
The CVEs security news mentioned most in May 2026.
- CVE-2026-20182Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability510.0
- CVE-2026-0300PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal39.8
- CVE-2026-20127Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability310.0
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place37.8
- CVE-2026-35616A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.39.8
- CVE-2026-41089Windows Netlogon Remote Code Execution Vulnerability39.8
- CVE-2026-41096Windows DNS Client Remote Code Execution Vulnerability39.8
- CVE-2024-55591An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2...29.8
- CVE-2025-55182A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, rea...210.0
- CVE-2026-0257PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities29.1
- CVE-2026-0265PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled29.8
- CVE-2026-32161Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability27.5