September 2026
10,681 CVEs so far, on pace for about 11,868. CISA has added 29 to KEV.
2026 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026 | January 2026: 5,244 CVEs17 added to CISA KEV | February 2026: 4,931 CVEs28 added to CISA KEV | March 2026: 6,821 CVEs26 added to CISA KEV | April 2026: 6,440 CVEs31 added to CISA KEV | May 2026: 7,365 CVEs21 added to CISA KEV | June 2026: 8,314 CVEs23 added to CISA KEV | July 2026: 10,240 CVEs26 added to CISA KEV | August 2026: 12,909 CVEs31 added to CISA KEV | September 2026 so far: 10,681 CVEs29 added to CISA KEV | 72,945+88%so far |
- Critical
- 94611% of the 8,912 with a CVSS score
- Added to CISA KEV
- 2914 of this month's CVEs are in KEV, listed a median 1 days after publication
- Vendors
- 1,6523,329 products
- Top weakness
- XSSCWE-79 · 728 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1LinuxLinux1,507107none—
- 2MicrosoftWindows Server 2025, Windows Server 2025 (Server Core Installation), Windows Server 20221,001602+1
- 3OracleOracle Hyperion Financial Management, Oracle Business Intelligence Enterprise Edition, Siebel Crm Deployment63497none−1
- 4GoogleChrome, Android, Go-attestation516593—
- 5IBMGuardium Data Protection, Langflow Oss, I29732none—
- 6ApplemacOS, iOS and iPadOS, iPadOS2468none+22
- 7DellSecure Connect Gateway 5.0 - Appliance, Secure Connect Gateway, Secure Connect Gateway 5.0 - Application17711none+6
- 8AdobeAdobe Experience Manager 6.5, Adobe Experience Manager 6.5 Lts, Adobe Experience Manager As A Cloud Service17171+2
- 9Red HatRed Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 101575none−3
- 10HPEFabric Composer, Edgeconnect SD-WAN Gateways, Aos-cx12912nonenew
- 11MozillaThunderbird, Firefox, Firefox Mobile11313none+6
- 12WwbnAvideo1066none+76
- 13CiscoCisco Identity Services Engine Software, Cisco ISE Passive Identity Connector, Cisco Secure Firewall Management Center (FMC)97322+12
- 14Apache Software FoundationApache Syncope, Apache Storm Nimbus, Apache Activemq Artemis9333none−7
- 15Concrete CMSConcrete CMS651nonenew
- 16SourcecodesterClass and Exam Timetabling System, Syllabus-aligned Learning Management & Examination System, Drug Recommendation System580none+8
- 17JenkinsJenkins, Jenkins Script Security Plugin, Jenkins Pipeline: Groovy Libraries Plugin530none+47
- 18Aruba NetworksFabric Composer525nonenew
- 19MongodbMongodb, Mongodb Server, C Driver500none+1
- 20GrokabilitySnipe-it460none+122
- 21Arista NetworksEOS, Velocloud Edge, Velocloud455nonenew
- 22SnipeitappSnipe-it440nonenew
- 23MispMisp, Sachertortephp433none+52
- 24ElasticKibana, Elasticsearch, Elastic Cloud On Kubernetes420none−2
- 25ApacheArtemis, Zookeeper, Apache-airflow-providers-fab3815none−17
Severity
How this month's CVEs score on CVSS; 1,769 have no score yet. Severity is not exploitation.
- Critical946
- High4,230
- Medium3,329
- Low407
Breakouts
Vendors with at least three times their own 12-month median.
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS728
- CWE-862Missing Authorization534
- CWE-284Improper Access Control491
- CWE-122Heap Buffer Overflow414
- CWE-416Use After Free361
- CWE-89SQL Injection324
- CWE-125Out-of-bounds Read317
- CWE-863Incorrect Authorization302
- CWE-269Improper Privilege Mgmt286
- CWE-22Path Traversal267
- CWE-200Information Exposure239
- CWE-306Missing Auth for Critical Function238
- CWE-639Auth Bypass via User Key232
- CWE-918SSRF230
- CWE-78OS Command Injection224
- CWE-400Resource Consumption189
- CWE-287Improper Authentication188
- CWE-787Out-of-bounds Write187
- CWE-94Code Injection184
- CWE-74Injection169
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Operating Systems3,17331% of sector-tagged CVEs
- Web & CMS Plugins1,07811% of sector-tagged CVEs
- Enterprise Software1,03210% of sector-tagged CVEs
- Consumer Software8749% of sector-tagged CVEs
- OSS Libraries7497% of sector-tagged CVEs
- Databases6106% of sector-tagged CVEs
- Networking Infrastructure6056% of sector-tagged CVEs
- Cloud & SaaS4214% of sector-tagged CVEs
- 7 smaller sectors1,502
- Not yet classified215
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 862Missing Authorization | 284Improper Access Control | 122Heap Buffer Overflow | 89SQL Injection | 416Use After Free | 863Incorrect Authorization | 125Out-of-bounds Read | 22Path Traversal | 200Information Exposure |
|---|---|---|---|---|---|---|---|---|---|---|
| Linux | ||||||||||
| Microsoft | 9 | 13 | 7 | 312 | 6 | 182 | 2 | 156 | 7 | 5 |
| Oracle Corporation | 341 | 7 | 3 | 1 | 26 | |||||
| 1 | 40 | 1 | 18 | 66 | 53 | 17 | 23 | |||
| IBM | 21 | 13 | 7 | 9 | 15 | 1 | 5 | 6 | 30 | 4 |
| Oracle | 142 | 5 | 3 | 5 | ||||||
| Apple | 1 | 11 | 17 | 2 | 13 | 15 | 22 | 14 | 14 | |
| Red Hat | 4 | 19 | 2 | 4 | 3 | 7 | 15 | 9 | 3 | |
| Adobe | 113 | 1 | 6 | 5 | 11 | 12 | 6 | 3 | ||
| Dell | 1 | 2 | 2 | 5 | 5 | 5 | 1 | |||
| Hewlett Packard Enterprise (HPE) | 5 | 8 | 1 | 6 | 1 | 4 | 13 | |||
| Apache Software Foundation | 8 | 11 | 4 | 11 | 4 | 4 |
In the news
The CVEs security news mentioned most in September 2026.
- CVE-2026-85046Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)198.8
- CVE-2026-85880Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability197.8
- CVE-2026-20079Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability1510.0
- CVE-2026-81963Windows Update Stack Elevation of Privilege Vulnerability137.8
- CVE-2026-82329Potential authentication bypass leading to administrative access in Artifactory139.8
- CVE-2026-20316Cisco Secure Firewall Management Center Software Static Credential Vulnerability125.3
- CVE-2026-85102Improper Certificate Validation in Quantum Security Gateway129.8
- CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)118.8
- CVE-2026-76461Cisco Secure Email Gateway SQL Injection Vulnerability109.8
- CVE-2026-83548A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit ...1010.0
- CVE-2026-83549Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) wh...107.8
- CVE-2026-86060SSH session privilege manipulation via a crafted username in Mikrotik RouterOS109.8