June 2026
8,314 CVEs published, +13% on May 2026 and 2.1× June 2025. CISA added 23 to KEV.
2026 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026 | January 2026: 5,244 CVEs17 added to CISA KEV | February 2026: 4,931 CVEs28 added to CISA KEV | March 2026: 6,821 CVEs26 added to CISA KEV | April 2026: 6,440 CVEs31 added to CISA KEV | May 2026: 7,365 CVEs21 added to CISA KEV | June 2026: 8,314 CVEs23 added to CISA KEV | July 2026: 10,240 CVEs26 added to CISA KEV | August 2026: 12,909 CVEs31 added to CISA KEV | September 2026 so far: 10,681 CVEs29 added to CISA KEV | 72,945+88%so far |
- Critical
- 91413% of the 7,187 with a CVSS score
- Added to CISA KEV
- 2315 of this month's CVEs are in KEV, listed a median 2 days after publication
- Vendors
- 1,9527,510 products
- Top weakness
- XSSCWE-79 · 663 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1GoogleChrome, Android, Google Chrome1,0951072+1
- 2LinuxLinux, Linux Kernel51440none−1
- 3MicrosoftWindows 11 26h1, Windows 11 Version 26h1, Windows Server 202526519none—
- 4OracleWebcenter Content, Oracle Webcenter Content, Enterprise Manager Base Platform2431231+35
- 5AdobeExperience Manager, Adobe Experience Manager, Acrobat Reader14512none+12
- 6Red HatRed Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 101322none—
- 7Apache Software FoundationApache Airflow, Apache Activemq, Apache HTTP Server12121none—
- 8ApacheAirflow, Activemq, HTTP Server11019none+2
- 9PyPIPraisonai, Praisonaiagents, Picklescan980none+22
- 10npmOpenclaw, Praisonai, Network-ai890none−2
- 11IBMWebsphere Application Server, Langflow Oss, Watsonx.data Intelligence7516none+9
- 12SpringSpring Framework, Spring Web Services, Spring Security720nonenew
- 13CapgoCapgo, Cli611nonenew
- 14OpenclawOpenclaw611none−3
- 15ThemerexLine Agency, Luxmed | Medicine & Healthcare Doctor WordPress Theme, Maxinet585nonenew
- 16Сообщество Свободного Программного ОбеспеченияDebian Gnu/linux, Xwayland, Gpac555none−12
- 17ApplemacOS, iPhone OS, iOS and iPadOS521none−12
- 18MozillaFirefox, Thunderbird, Firefox For IOS509none+6
- 19SourcecodesterClass and Exam Timetabling System, Pharmacy Sales and Inventory System, Inventory System490none+16
- 20VMwareSpring Framework, Spring Security, Spring Data Rest440none+137
- 21ItsourcecodeHospital Management System, Fees Management System, Online Hotel Management System430none+63
- 22ImagemagickImagemagick410nonenew
- 23DellPowerflex Manager, Powerflex, Wyse Management Suite381none+31
- 24JenkinsJenkins, Jenkins Assembla Plugin, Jenkins Contrast Continuous Application Security Plugin360none+68
- 25GoGithub.com/klever-io/klever-go, Github.com/gohugoio/hugo, Github.com/go-chi/chi/v5/middleware350none+4
Severity
How this month's CVEs score on CVSS; 1,127 have no score yet. Severity is not exploitation.
- Critical914
- High3,202
- Medium2,813
- Low258
Breakouts
Vendors with at least three times their own 12-month median.
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS663
- CWE-416Use After Free436
- CWE-89SQL Injection406
- CWE-862Missing Authorization389
- CWE-284Improper Access Control371
- CWE-20Improper Input Validation367
- CWE-22Path Traversal317
- CWE-125Out-of-bounds Read214
- CWE-200Information Exposure186
- CWE-502Deserialization185
- CWE-306Missing Auth for Critical Function184
- CWE-78OS Command Injection182
- CWE-639Auth Bypass via User Key174
- CWE-74Injection172
- CWE-918SSRF171
- CWE-787Out-of-bounds Write169
- CWE-863Incorrect Authorization162
- CWE-94Code Injection153
- CWE-400Resource Consumption146
- CWE-121130
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- OSS Libraries1,51317% of sector-tagged CVEs
- Web & CMS Plugins1,47616% of sector-tagged CVEs
- Consumer Software1,40115% of sector-tagged CVEs
- Operating Systems1,20113% of sector-tagged CVEs
- Enterprise Software93410% of sector-tagged CVEs
- Cloud & SaaS4024% of sector-tagged CVEs
- Networking Infrastructure3834% of sector-tagged CVEs
- 8 smaller sectors1,648
- Not yet classified203
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 416Use After Free | 89SQL Injection | 862Missing Authorization | 284Improper Access Control | 20Improper Input Validation | 22Path Traversal | 125Out-of-bounds Read | 502Deserialization | 787Out-of-bounds Write |
|---|---|---|---|---|---|---|---|---|---|---|
| 15 | 268 | 2 | 15 | 43 | 219 | 3 | 60 | 33 | ||
| Linux | 74 | 1 | 31 | 29 | ||||||
| Oracle Corporation | 3 | 159 | 1 | 1 | ||||||
| Oracle | 3 | 159 | 1 | 1 | ||||||
| Microsoft Corp | 21 | 51 | 1 | 9 | 15 | 3 | 22 | 3 | 14 | |
| Microsoft | 24 | 47 | 2 | 8 | 6 | 3 | 21 | 3 | 12 | |
| Adobe | 60 | 13 | 1 | 11 | 5 | 9 | 10 | |||
| Red Hat | 3 | 7 | 3 | 1 | 4 | 15 | 6 | |||
| Apache Software Foundation | 4 | 2 | 2 | 3 | 9 | 5 | 2 | 6 | ||
| Adobe Systems Inc. | 58 | 11 | 1 | 8 | 2 | 4 | 7 | |||
| PyPI | 5 | 1 | 6 | 1 | 3 | 21 | 1 | 10 | 1 | |
| Apache | 4 | 2 | 2 | 3 | 9 | 3 | 2 | 6 |
In the news
The CVEs security news mentioned most in June 2026.
- CVE-2026-35273Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily explo...239.8
- CVE-2026-20245Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability197.8
- CVE-2026-45586Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability197.8
- CVE-2026-20230Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability158.6
- CVE-2026-45585Windows BitLocker Security Feature Bypass Vulnerability156.8
- CVE-2026-50507Windows BitLocker Security Feature Bypass Vulnerability156.8
- CVE-2026-33825Microsoft Defender Elevation of Privilege Vulnerability147.8
- CVE-2026-41091Microsoft Defender Elevation of Privilege Vulnerability137.8
- CVE-2026-50751User Authentication Bypass in VPN Remote Access and Mobile Access139.3
- CVE-2026-10520An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution1210.0
- CVE-2026-49160HTTP.sys Denial of Service Vulnerability127.5
- CVE-2026-20253Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise119.8