CVE Intelligence
Skip to main content

Month report

June 2026

Rolled up 2026-09-14 09:26 from 370,877 CVE records

7,952 CVEs published, +116% on the same month last year. 933 rated critical, 23 listed by CISA as exploited. google led with 1,090; the most common weakness class was CWE-79 (637). codeastro climbed 66 places, the largest move. 8 vendors ranked for the first time.

Published

7,952

+14.6%on the previous month

Critical / high

933 / 3,345

of the 7,674 scored

Medium / low

3,047 / 349

the rest of the scored bands

Added to CISA KEV

23

listed as exploited this month

Public exploit

286

exploit code indexed publicly

Scanner template

58

0.7% of the month

Publication to KEV

How long before CISA listed them

24 published this month and listed since — not the 23 listed during it.

Median days to listing

7.5

from publication to CISA's date added

Listed within 7 days

50%

of the 24

Listed within 30 days

83.3%

of the 24

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-79CWE-416CWE-89CWE-862CWE-284CWE-20CWE-22CWE-125
google1526811443214260
linux31
redhat81753171019
oracle31591
microsoft2142286319
adobe601311159
apache3223952
ibm8111

Detection gap

Listed as exploited, no public template

CVEs CISA listed this month

Listed this month

23

added to the CISA KEV catalog

With a template

9

39.1% covered

No template

14

nothing in the public index

Measured against the nuclei-templates CVE index only. No template there does not mean a CVE is undetectable by any other tool.

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2026-06, sorted by CVEs descending
#VendorTop products
1google1,090121227chrome (965) · android (117) · mcp toolbox for databases googleapis mcp toolbox (4)↑1
2linux5134010linux (513) · red hat enterprise linux 10 (49) · red hat enterprise linux 8 (49)↓1
3redhat3303129red hat enterprise linux 8 (197) · red hat enterprise linux 9 (195) · red hat enterprise linux 10 (182)
4oracle242123131oracle webcenter content (29) · jd edwards enterpriseone tools (14) · oracle enterprise manager base platform (14)↑22
5microsoft221156windows 11 version 26h1 (111) · windows server 2025 (109) · windows server 2025 server core installation (109)↓1
6adobe14312112adobe experience manager 6 5 (57) · adobe experience manager 6 5 lts (57) · adobe experience manager as a cloud service (57)↑6
7apache1211682apache airflow (17) · apache activemq (15) · apache http server (13)↓1
8ibm75162websphere application server (16) · langflow oss (14) · watsonx data intelligence (10)↑7
9spring723spring framework (18) · spring security (7) · spring web services (7)·
10capgo611capgo (60) · cli (1)new
11openclaw61openclaw (61)↓3
12themerex585abelle (1) · airsupply (1) · autoparts (1)·
13apple5213macos (49) · ios and ipados (38) · watchos (34)↓8
14mozilla5082firefox (45) · thunderbird (42) · red hat enterprise linux 10 (16)↑4
15sourcecodester491class and exam timetabling system (16) · pharmacy sales and inventory system (6) · inventory system (3)↑7
16itsourcecode43hospital management system (16) · fees management system (9) · online hotel management system (6)↑40
17siemens4343linux (30) · simatic s7 1500 cpu 1518 4 pn dp mfp (30) · simatic s7 1500 cpu 1518f 4 pn dp mfp (30)↓10
18imagemagick411imagemagick (41) · red hat enterprise linux 6 (10) · red hat enterprise linux 7 extended lifecycle support (8)·
19dell381powerflex (10) · display and peripheral manager (4) · wyse management suite wms (4)↑17
20jenkins project361jenkins (8) · jenkins assembla plugin (3) · jenkins contrast continuous application security plugin (3)↑41
21picklescan348picklescan (34)new
22wolfssl321wolfssl (32)·
23nocodb291nocodb (29)·
24misp2851misp (27) · bsimvis (1)↑62
25acer267connect m6e 5g portable wifi router (26)↑46
26codeastro26human resource management system (7) · leave management system (5) · student attendance management system (5)↑66
27frappe26frappe framework (12) · frappe (11) · erpnext (2)↑56
28nextcloud261security advisories (26)·
29netty252netty (22) · red hat build of apache camel 4 18 1 p1 for spring boot 3 5 16 (13) · red hat data grid 8 6 2 (13)↑34
30zephyrproject251zephyr (25)new
31gitlab24gitlab (24)↓4
32gogs24332gogs (24)·
33qnap systems2411quts hero (13) · qts (12) · file station 5 (6)·
34flowise23833flowise (23) · flowise components (1)new
35qualcomm22snapdragon (22)↑56
36n8n io2131n8n (21)↑30
37mattermost20mattermost (18) · github com mattermost mattermost server public (1) · mattermost google drive plugin (1)↓16
38geovision19121gv lpclpc2011 2211 (10) · gv i o box 4e (8) · geovision (1)↑37
39openssl1811openssl (18) · cost management 4 (1) · multicluster engine for kubernetes (1)·
40angular17angular (17) · red hat enterprise linux 8 (2) · red hat fuse 7 (2)new
41code projects175hotel and tourism reservation system (4) · online hospital management system (3) · online music site (3)↓10
42fission175fission (17)new
43gen digital17avast antivirus (8) · avast business antivirus (8) · avast one (8)new
44netgear17raxe500 (6) · raxe450 (5) · xr1000 (5)·
45open webui17open webui (17)↓35
46opf174openproject (17)·
47revive17adserver (17)·
48tenda1712jd12l (5) · hg10 (3) · hg7hg9 (3)↑2
49arista networks16211eos (8) · arista edge threat management arista next generation firewall ngfw (5) · eos cloudvision exchange cvx (3)·
50dr ger16infinity acute care system (2) · infinity delta (2) · infinity delta xl (2)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2026-06 that are on the CISA KEV catalog today. The 23 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-7963721 critical
  • 2CWE-41642246 critical↑4
  • 3CWE-8940088 critical↓1
  • 4CWE-86236723 critical↓1
  • 5CWE-284362106 critical↑7
  • 6CWE-2035559 critical↑4
  • 7CWE-2228038 critical↓3
  • 8CWE-1252047 critical↑10
  • 9CWE-50218256 critical↑17
  • 10CWE-2001719 critical↑9
  • 1CWE-741700 critical
  • 2CWE-7817045 critical↓7
  • 3CWE-30616569 critical↑12
  • 4CWE-63916511 critical↑1
  • 5CWE-9181516 critical↓6
  • 6CWE-78715013 critical↑4
  • 7CWE-9414544 critical↓10
  • 8CWE-8631389 critical↓4
  • 9CWE-4001364 critical↑3
  • 10CWE-12113018 critical↓3

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.