CVE Intelligence
Skip to main content

Month report

August 2026

Rolled up 2026-09-12 08:45 from 370,661 CVE records

10,633 CVEs published, +193% on the same month last year. 1,506 rated critical, 31 listed by CISA as exploited. linux led with 1,500; the most common weakness class was CWE-284 (1,077). siyuan note climbed 80 places, the largest move. 6 vendors ranked for the first time.

Published

10,633

+8.9%on the previous month

Critical / high

1,506 / 4,695

of the 9,912 scored

Medium / low

3,365 / 346

the rest of the scored bands

Added to CISA KEV

31

listed as exploited this month

Public exploit

249

exploit code indexed publicly

Scanner template

32

0.3% of the month

Publication to KEV

How long before CISA listed them

17 published this month and listed since — not the 31 listed during it.

Median days to listing

3

from publication to CISA's date added

Listed within 7 days

70.6%

of the 17

Listed within 30 days

100%

of the 17

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-284CWE-79CWE-862CWE-89CWE-22CWE-918CWE-639CWE-78
linux
oracle745
microsoft71312341432
ibm2337243128
redhat464953
apache3451762
splunk58123552
adobe43334

Detection gap

Listed as exploited, no public template

CVEs CISA listed this month

Listed this month

31

added to the CISA KEV catalog

With a template

10

32.3% covered

No template

21

nothing in the public index

Measured against the nuclei-templates CVE index only. No template there does not mean a CVE is undetectable by any other tool.

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2026-08, sorted by CVEs descending
#VendorTop products
1linux1,5001957linux (1500)↑1
2oracle889144helidon (99) · oracle hyperion financial management (78) · oracle hyperion infrastructure technology (67)↓1
3microsoft47735111windows server 2025 (213) · windows server 2025 server core installation (213) · windows 11 version 26h1 (194)
4ibm381503aix (145) · powervm vios (145) · i (106)↑5
5redhat2142131red hat enterprise linux 9 (91) · red hat enterprise linux 8 (87) · red hat enterprise linux 7 (76)↑2
6apache1452612apache cloudstack (20) · apache airflow (12) · apache cxf (12)↓1
7splunk1104splunk enterprise (60) · splunk soar (15) · splunk ai toolkit (9)·
8adobe981511content credentials rust sdk (21) · coldfusion 2023 (16) · coldfusion 2025 (16)
9siyuan note761621siyuan (76)↑80
10google74112chrome (69) · android (2) · a2ui web core (1)↓6
11getgrav643grav (53) · grav plugin api (7) · grav plugin login (3)↑11
12mozilla59175firefox (59) · thunderbird (55)↓2
13dell583dell command update dcu (11) · openmanage enterprise (10) · objectscale (7)↑4
14zephyrproject541zephyr (54)↑16
15elastic49kibana (31) · elasticsearch (14) · eck operator (2)↑13
16gitea498111gitea open source git server (47) · gitea (2)↑4
17sourcecodester48simple online food ordering system (13) · class and exam timetabling system (8) · photo share website (5)↓4
18cisco461312cisco ios xe software (12) · cisco secure endpoint (7) · cisco catalyst sd wan manager (6)↑43
19apple40116ios and ipados (32) · macos (30) · safari (21)↓13
20draytek403vigorswitch fx2120 (29) · vigorswitch g1280 (29) · vigorswitch g1282 (29)·
21dokploy3723dokploy (37)·
22flowiseai371721flowise (37) · flowise components (1)·
23freerdp374freerdp (37)·
24sap se3531sap business ai platform approuter (11) · sap manufacturing integration and intelligence (5) · odata (1)↑41
25legion of the bouncy castle3441bc java (32) · bc lts java (28) · bc fja (25)·
26mediatek34mediatek chipset (34)·
27n8n io34n8n (34)↑28
28nvidia3422dynamo (15) · triton inference server (6) · dgx spark (5)↓10
29tp link systems3414omada access points (7) · omada gateways (7) · omada switches (7)·
30mongodb331mongodb server (24) · bi connector odbc driver (5) · schema builder cli (2)↑2
31rsyncproject3311rsync (33)new
32itsourcecode32hospital management system (19) · sales and inventory system (5) · payroll system (2)↑22
33jahlives3115openssl encrypt (31)new
34jfrog301321artifactory (30)↑48
35budibase2851budibase (21) · server (7)·
36wireshark foundation28wireshark (28)↑60
37samsung mobile27samsung mobile devices (16) · smart switch (4) · samsung health (3)↑14
38arcadedata2562arcadedb (25)new
39code projects25online shopping system (7) · task management system (6) · barangay resident profiling management system (3)↓14
40typo3252extension apache solr for typo3 enterprise search (5) · extension femanager (4) · extension event management and registration (2)·
41gitpython developers242gitpython (24)new
42jenkins project241jenkins (6) · jenkins multijob plugin (2) · jenkins scm manager plugin (2)·
43nltk243nltk (21) · nltk nltk (3)new
44freebsd23freebsd (23)·
45frappe222frappe (13) · erpnext (9)·
46mervinpraison222praisonai (21) · praisonaiagents (5) · praisonai platform (1)↓34
47tobit laboratories225teamdavid (22)new
48combodo211itop (21)·
49gl inet2110gl mt3000 (13) · mt6000 (6) · x3000 (6)·
50misp20cti transmute (16) · misp stix (4)·

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2026-08 that are on the CISA KEV catalog today. The 31 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-2841,077194 critical
  • 2CWE-7964616 critical
  • 3CWE-86252144 critical
  • 4CWE-89393107 critical↑1
  • 5CWE-2237840 critical↑2
  • 6CWE-91829820 critical↑6
  • 7CWE-63927824 critical↑6
  • 8CWE-7827087 critical↑10
  • 9CWE-20024312 critical↓3
  • 10CWE-86323825 critical↑1
  • 1CWE-9422589 critical↑8
  • 2CWE-78721630 critical↑8
  • 3CWE-1252113 critical↑1
  • 4CWE-12220410 critical↑2
  • 5CWE-7420018 critical↑7
  • 6CWE-30619867 critical↓12
  • 7CWE-2016821 critical↓8
  • 8CWE-41616015 critical↓10
  • 9CWE-28715942 critical↓2
  • 10CWE-7701562 critical↑1

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.