August 2026
12,909 CVEs published, +26% on July 2026 and 3.3× August 2025. CISA added 31 to KEV.
2026 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026 | January 2026: 5,244 CVEs17 added to CISA KEV | February 2026: 4,931 CVEs28 added to CISA KEV | March 2026: 6,821 CVEs26 added to CISA KEV | April 2026: 6,440 CVEs31 added to CISA KEV | May 2026: 7,365 CVEs21 added to CISA KEV | June 2026: 8,314 CVEs23 added to CISA KEV | July 2026: 10,240 CVEs26 added to CISA KEV | August 2026: 12,909 CVEs31 added to CISA KEV | September 2026 so far: 10,681 CVEs29 added to CISA KEV | 72,945+88%so far |
- Critical
- 1,58915% of the 10,466 with a CVSS score
- Added to CISA KEV
- 3114 of this month's CVEs are in KEV, listed a median 2.5 days after publication
- Vendors
- 2,1515,622 products
- Top weakness
- Improper Access ControlCWE-284 · 1,202 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1LinuxLinux1,645212none+1
- 2OracleHelidon, Hyperion Financial Management, Oracle Hyperion Financial Management890144none−1
- 3MicrosoftWindows Server 2025 (Server Core Installation), Windows Server 2025, Windows 11 26h1479351—
- 4GoogleChrome, Android, @a2ui/web_core40254none—
- 5IBMPowervm Vios, Aix, Vios39051none+6
- 6Red HatRed Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 722821none+1
- 7Apache Software FoundationApache Cloudstack, Apache Airflow, Apache Cxf16739none−2
- 8ApacheCloudstack, Airflow, Cxf16339none+1
- 9SplunkSplunk Enterprise, Splunk, Splunk Soar1104nonenew
- 10AdobeContent Credentials Rust Sdk, C2PA, C2PATOOL10115none—
- 11SpringSpring Framework, Spring Integration, Spring AI917nonenew
- 12Siyuan-noteSiyuan8116none+97
- 13DellCommand Update, Dell Command Update (Dcu), Openmanage Enterprise725none+6
- 14GetgravGrav, Grav-plugin-api, Grav-plugin-login663none+10
- 15JahlivesOpenssl_encrypt, OpenSSL Encrypt6618nonenew
- 16VMwareSpring Integration, Spring Framework, Spring Security647none+94
- 17MozillaFirefox, Thunderbird, Firefox Mobile6017none−5
- 18ZephyrprojectZephyr571none+19
- 19PyPINltk, Gitpython, Wagtail560none+10
- 20MongodbMongodb Server, Bi Connector, Bi Connector Odbc Driver551none+20
- 21NvidiaDynamo, Nemoclaw, Triton Inference Server524none−1
- 22ElasticKibana, Elasticsearch, Elastic Cloud On Kubernetes490none+11
- 23GiteaGitea Open Source Git Server, Gitea4981—
- 24SourcecodesterSimple Online Food Ordering System, Class and Exam Timetabling System, Photo Share Website490none−8
- 25CiscoCisco IOS XE Software, Cisco Secure Endpoint, IOS XE48131+30
Severity
How this month's CVEs score on CVSS; 2,443 have no score yet. Severity is not exploitation.
- Critical1,589
- High4,889
- Medium3,608
- Low380
Breakouts
Vendors with at least three times their own 12-month median.
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-284Improper Access Control1,202
- CWE-79XSS769
- CWE-862Missing Authorization627
- CWE-89SQL Injection452
- CWE-22Path Traversal451
- CWE-918SSRF356
- CWE-863Incorrect Authorization335
- CWE-639Auth Bypass via User Key332
- CWE-200Information Exposure329
- CWE-78OS Command Injection313
- CWE-94Code Injection263
- CWE-20Improper Input Validation251
- CWE-787Out-of-bounds Write247
- CWE-125Out-of-bounds Read237
- CWE-74Injection233
- CWE-306Missing Auth for Critical Function228
- CWE-122Heap Buffer Overflow224
- CWE-416Use After Free220
- CWE-269Improper Privilege Mgmt207
- CWE-770Allocation Without Limits195
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Operating Systems2,69322% of sector-tagged CVEs
- Enterprise Software1,59113% of sector-tagged CVEs
- Web & CMS Plugins1,41811% of sector-tagged CVEs
- OSS Libraries1,30811% of sector-tagged CVEs
- Consumer Software1,0338% of sector-tagged CVEs
- Databases9368% of sector-tagged CVEs
- Cloud & SaaS8697% of sector-tagged CVEs
- Networking Infrastructure5484% of sector-tagged CVEs
- Security Products5324% of sector-tagged CVEs
- 6 smaller sectors1,360
- Not yet classified106
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 284Improper Access Control | 79XSS | 862Missing Authorization | 22Path Traversal | 89SQL Injection | 918SSRF | 863Incorrect Authorization | 639Auth Bypass via User Key | 200Information Exposure | 78OS Command Injection |
|---|---|---|---|---|---|---|---|---|---|---|
| Linux | ||||||||||
| Oracle Corporation | 818 | 20 | ||||||||
| Oracle | 812 | 19 | ||||||||
| Microsoft | 7 | 13 | 12 | 4 | 3 | 14 | 7 | 3 | 8 | 2 |
| 1 | 1 | 22 | 51 | 35 | 1 | |||||
| IBM | 2 | 3 | 3 | 24 | 7 | 4 | 2 | 3 | 5 | 28 |
| Red Hat | 4 | 6 | 4 | 9 | 5 | 8 | 1 | 3 | ||
| Apache Software Foundation | 4 | 6 | 4 | 2 | 5 | 8 | 7 | 6 | 10 | 2 |
| Apache | 4 | 6 | 4 | 2 | 5 | 8 | 7 | 5 | 10 | 2 |
| Splunk | 5 | 8 | 12 | 5 | 3 | 5 | 4 | 2 | 4 | |
| Adobe | 4 | 3 | 3 | 3 | 15 | 4 | ||||
| Spring | 3 | 4 | 4 | 4 | 1 |
In the news
The CVEs security news mentioned most in August 2026.
- CVE-2026-68820Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability227.0
- CVE-2026-18577Incomplete patch leads to administrative account takeover178.1
- CVE-2026-55040Microsoft SharePoint Server Security Feature Bypass Vulnerability159.1
- CVE-2026-18556Unauthenticated administrative account takeover147.4
- CVE-2026-19478Improper Control of Generation of Code ('Code Injection') in GitLab139.4
- CVE-2026-62832Windows User Profile Service Elevation of Privilege Vulnerability137.8
- CVE-2026-63520Microsoft SharePoint Server Remote Code Execution Vulnerability138.1
- CVE-2026-65400An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. A...139.8
- CVE-2026-50656Microsoft Defender Elevation of Privilege Vulnerability107.8
- CVE-2026-62878Windows DNS Server Remote Code Execution Vulnerability109.8
- CVE-2026-66066Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing10—
- CVE-2026-19490NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-1949099.8