July 2026
10,240 CVEs published, +23% on June 2026 and 2.5× July 2025. CISA added 26 to KEV.
2026 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026 | January 2026: 5,244 CVEs17 added to CISA KEV | February 2026: 4,931 CVEs28 added to CISA KEV | March 2026: 6,821 CVEs26 added to CISA KEV | April 2026: 6,440 CVEs31 added to CISA KEV | May 2026: 7,365 CVEs21 added to CISA KEV | June 2026: 8,314 CVEs23 added to CISA KEV | July 2026: 10,240 CVEs26 added to CISA KEV | August 2026: 12,909 CVEs31 added to CISA KEV | September 2026 so far: 10,681 CVEs29 added to CISA KEV | 72,945+88%so far |
- Critical
- 1,21814% of the 8,704 with a CVSS score
- Added to CISA KEV
- 2613 of this month's CVEs are in KEV, listed a median 0 days after publication
- Vendors
- 1,9564,770 products
- Top weakness
- Improper Access ControlCWE-284 · 913 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1OracleOracle Coherence, Coherence, Webcenter Content1,108210none+3
- 2LinuxLinux, Linux Kernel83788none—
- 3MicrosoftWindows Server 2025 (Server Core Installation), Windows Server 2025, Windows 11 Version 26h1664354—
- 4GoogleChrome, Mcp-toolbox, Mcp Toolbox For Databases (Googleapis/mcp-toolbox)49678none−3
- 5Apache Software FoundationApache Traffic Server, Apache Camel, Apache Thrift18146none+2
- 6ApplemacOS, iOS and iPadOS, iPadOS16755none+11
- 7Red HatRed Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 81646none−1
- 8npmN8N, Openclaw, @budibase/server1580none+2
- 9ApacheCamel, Thrift, Traffic Server11631none−1
- 10AdobeColdfusion, Commerce, Adobe Bridge10715none−5
- 11IBMLangflow Oss, Websphere Application Server, Websphere Application Server - Liberty10525none—
- 12MozillaFirefox, Thunderbird, Firefox Mobile7139none+6
- 13SurrealdbSurrealdb570nonenew
- 14SymfonySymfony, Twig, Ux568nonenew
- 15PraisonPraisonai, Praisonai-platform, Praisonaiagents5411nonenew
- 16SourcecodesterClass and Exam Timetabling System, Multi-vendor Online Grocery Management System, Simple and Nice Shopping Cart Script490none+3
- 17DrupalDrupal, Drupal Core, Drupal Canvas465nonenew
- 18OpenclawOpenclaw, Msteams, Feishu440none−4
- 19DellPowerprotect Data Domain, Data Domain Operating System, Powerprotect Data Manager435none+4
- 20NvidiaTensorrt-llm, Megatron-bridge, Nemo Megatron Bridge433nonenew
- 21Crates.ioSurrealdb, Zebrad, Hubuum_client410none+107
- 22HclsoftwareAftermarket Epc, Mycloud, Intelliops Event Management410none+115
- 23GiteaGitea Open Source Git Server4011nonenew
- 24GetgravGrav383nonenew
- 25ImagemagickImagemagick370none−3
Severity
How this month's CVEs score on CVSS; 1,536 have no score yet. Severity is not exploitation.
- Critical1,218
- High3,888
- Medium3,229
- Low369
Breakouts
Vendors with at least three times their own 12-month median.
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-284Improper Access Control913
- CWE-79XSS765
- CWE-862Missing Authorization477
- CWE-89SQL Injection394
- CWE-306Missing Auth for Critical Function393
- CWE-200Information Exposure370
- CWE-22Path Traversal333
- CWE-416Use After Free332
- CWE-863Incorrect Authorization288
- CWE-20Improper Input Validation273
- CWE-918SSRF261
- CWE-639Auth Bypass via User Key255
- CWE-269Improper Privilege Mgmt252
- CWE-125Out-of-bounds Read234
- CWE-400Resource Consumption222
- CWE-287Improper Authentication204
- CWE-122Heap Buffer Overflow196
- CWE-78OS Command Injection195
- CWE-94Code Injection184
- CWE-787Out-of-bounds Write162
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Operating Systems1,98919% of sector-tagged CVEs
- Web & CMS Plugins1,39413% of sector-tagged CVEs
- OSS Libraries1,33713% of sector-tagged CVEs
- Enterprise Software1,24012% of sector-tagged CVEs
- Databases1,09110% of sector-tagged CVEs
- Consumer Software1,02110% of sector-tagged CVEs
- Cloud & SaaS4845% of sector-tagged CVEs
- Networking Infrastructure4414% of sector-tagged CVEs
- 7 smaller sectors1,450
- Not yet classified128
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 284Improper Access Control | 79XSS | 862Missing Authorization | 89SQL Injection | 306Missing Auth for Critical Function | 416Use After Free | 200Information Exposure | 22Path Traversal | 863Incorrect Authorization | 20Improper Input Validation |
|---|---|---|---|---|---|---|---|---|---|---|
| Oracle Corporation | 682 | 10 | 3 | 6 | 258 | 111 | 7 | 17 | ||
| Oracle | 682 | 10 | 3 | 6 | 257 | 111 | 7 | 17 | ||
| Linux | 79 | |||||||||
| Microsoft | 26 | 18 | 7 | 2 | 8 | 141 | 33 | 6 | 3 | 10 |
| 14 | 13 | 1 | 92 | 10 | 5 | 92 | ||||
| Apache Software Foundation | 5 | 1 | 2 | 5 | 4 | 3 | 9 | 12 | 3 | 29 |
| Apache | 3 | 1 | 2 | 5 | 3 | 3 | 9 | 11 | 2 | 27 |
| Apple | 11 | 2 | 13 | 18 | 5 | 1 | 4 | |||
| Red Hat | 5 | 1 | 9 | 4 | 1 | 3 | 3 | 5 | 3 | |
| npm | 6 | 7 | 15 | 6 | 3 | 11 | 7 | 22 | 4 | |
| Adobe | 14 | 3 | 2 | 1 | 6 | 12 | 10 | |||
| IBM | 1 | 8 | 1 | 2 | 6 | 2 | 8 | 2 | 1 |
In the news
The CVEs security news mentioned most in July 2026.
- CVE-2026-56164Microsoft SharePoint Server Elevation of Privilege Vulnerability255.3
- CVE-2025-66376Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.177.2
- CVE-2025-3248Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code169.8
- CVE-2026-56155Active Directory Federation Services Elevation of Privilege Vulnerability167.8
- CVE-2026-58644Microsoft SharePoint Remote Code Execution Vulnerability169.8
- CVE-2026-50522Microsoft SharePoint Remote Code Execution Vulnerability159.8
- CVE-2026-60137WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query155.9
- CVE-2026-15409A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make...1410.0
- CVE-2026-15410Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could ...147.2
- CVE-2026-48282ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)1410.0
- CVE-2026-63030WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution149.8
- CVE-2026-16232Authentication Bypass in the SmartConsole Login Process Using an Application Token129.8