Solution sectors / cloud-saas
Cloud & SaaS
Cloud platforms, SaaS applications and the virtualization and container layers beneath them concentrate enormous amounts of data and compute. This hub follows CVE trends across cloud-native infrastructure.
saas-application · 120container-orchestration · 65cloud-platform · 59api-gateway · 7virtualization · 5
Cumulative CVEs
12,402
across 268 monthly snapshots
Latest month
526 · proj
-39.5% MoM · +289.6% YoY
Peak month
869
Aug 26
KEV this month
0
42 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Mixed71%
- On-prem18%
- SaaS11%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Cloud & SaaS.
- CVE-2026-91200DevSpace through 6.3.21 Path Traversal via tar extraction8.8
- CVE-2026-53714Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceMode7.4
- CVE-2026-53716Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit6.5
- CVE-2026-53715Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock5.3
- CVE-2026-53719Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization6.5
- CVE-2026-53718Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass6.4
- CVE-2026-53713Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure9.1
- CVE-2026-53717Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header6.5
- CVE-2026-16335DataStage on Cloud Pak for Data has several vulnerabilities due to open source software8.1
- CVE-2026-16338DataStage on Cloud Pak for Data has several vulnerabilities due to open source software9.9
- CVE-2026-16432DataStage on Cloud Pak for Data has several vulnerabilities due to open source software7.7
- CVE-2026-16428DataStage on Cloud Pak for Data has several vulnerabilities due to open source software8.8
- CVE-2026-16466DataStage on Cloud Pak for Data has several vulnerabilities due to open source software8.8
- CVE-2026-16673DataStage on Cloud Pak for Data has several vulnerabilities due to open source software8.8
- CVE-2026-86830Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center7.2
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| saas-application | 120 | 4 | · | 15 | — | microsoft 365 (84) · n8n (19) · iubenda | all-in-one compliance for gdpr / ccpa cookie consent + more (2) |
| container-orchestration | 65 | 3 | · | 8 | — | n8n (26) · red hat openshift container platform 4 (15) · nuclio (7) |
| cloud-platform | 59 | 9 | · | 9 | — | datastage on cloud pak for data (18) · plesk (4) · configserver security & firewall (3) |
| api-gateway | 7 | · | · | 2 | — | consul (4) · wso2 api control plane (3) · wso2 api manager (3) |
| — | 7 | 1 | · | 5 | — | canva (2) · red hat openshift ai (rhoai) (2) · identity server as key manager (1) |
| virtualization | 5 | 1 | · | 3 | — | xen (3) · opennebula (1) · proxmox virtual environment (ve) (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification