Solution sectors / cloud-saas
Cloud & SaaS
Cloud platforms, SaaS applications and the virtualization and container layers beneath them concentrate enormous amounts of data and compute. This hub follows CVE trends across cloud-native infrastructure.
saas-application · 123container-orchestration · 83cloud-platform · 32virtualization · 14api-gateway · 11
Cumulative CVEs
11,079
across 266 monthly snapshots
Latest month
336 · proj
-16.4% MoM · +246.4% YoY
Peak month
402
Jun 26
KEV this month
0
74 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Mixed56%
- On-prem44%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Cloud & SaaS.
- CVE-2026-62835Azure Portal Information Disclosure Vulnerability9.3
- CVE-2026-17107Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster8.5
- CVE-2026-66006lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs5.3
- CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability10.0
- CVE-2026-16730Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup5.5
- CVE-2026-16910Quay: ssrf in red hat quay notification webhooks (slack/generic)5.5
- CVE-2026-66139OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.4.8
- CVE-2026-66138In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed con...7.2
- CVE-2026-54422In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.5.5
- CVE-2026-56165Microsoft Account Remote Code Execution Vulnerability9.8
- CVE-2025-71389Cal.com before 5.9.9 Remote Code Execution via RSC10.0
- CVE-2024-58355Cal.com through 4.7.15 Cross-Site Scripting via booking questions8.9
- CVE-2024-58354cal.com Repository Takeover via pull_request_target Workflow9.9
- CVE-2024-58353Cal.com through 4.7.15 Cross-Site Scripting via booking questions8.9
- CVE-2026-16763localstack serverless-localstack Configuration index.js os command injection5.3
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| saas-application | 123 | 8 | · | 22 | — | microsoft 365 (71) · n8n (19) · hedgedoc (4) |
| container-orchestration | 83 | 9 | · | 16 | — | coolify (34) · containerd (6) · red hat openshift container platform 4 (6) |
| cloud-platform | 32 | 5 | · | 10 | — | owncloud 10 (4) · cloudreve (3) · cordyscrm (2) |
| — | 30 | 3 | · | 11 | — | rabbitmq server (11) · red hat openshift ai (rhoai) (8) · identity server as key manager (2) |
| virtualization | 14 | 9 | · | 8 | — | xapi (6) · xcp-ng (5) · xenserver (5) |
| api-gateway | 11 | · | · | 7 | — | api manager (4) · wso2 api manager (4) · amf (2) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification