Solution sectors / cloud-saas
Cloud & SaaS
Cloud platforms, SaaS applications and the virtualization and container layers beneath them concentrate enormous amounts of data and compute. This hub follows CVE trends across cloud-native infrastructure.
Cumulative CVEs
11,382
across 267 monthly snapshots
Latest month
289 · proj
-40.3% MoM · +155.8% YoY
Peak month
484
Jul 26
KEV this month
0
28 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem81%
- Mixed12%
- SaaS7%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Cloud & SaaS.
- CVE-2026-72508Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)9.9
- CVE-2026-19643Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms5.3
- CVE-2026-19642Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp5.9
- CVE-2026-73268Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection9.9
- CVE-2026-73269Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa9.9
- CVE-2026-73406Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint7.5
- CVE-2026-73308Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders5.7
- CVE-2026-73306Budibase: Account Enumeration via Login Lockout Response Differential5.3
- CVE-2026-73303Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)8.2
- CVE-2026-18952Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin8.1
- CVE-2026-19311Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin8.1
- CVE-2026-73301Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings4.3
- CVE-2026-73300Budibase: SQL Injection via `multipleStatements: true`9.6
- CVE-2026-19548Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing5.5
- CVE-2026-57858Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID8.9
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| wso2 | 19 | 5 | · |
| veeam | 10 | · | · |
| hashicorp | 8 | · | · |
| aws | 7 | · | · |
| openstack | 5 | · | · |
| kata-containers | 3 | 1 | · |
| amazon | 2 | · | · |
| gitroomhq | 2 | 1 | · |
| go-vikunja | 2 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| saas-application | 30 | 5 | · | 13 | — | one (6) · service provider console (4) · postiz-app (2) |
| container-orchestration | 29 | 3 | · | 5 | — | red hat openshift container platform 4 (14) · consul enterprise (8) · kata-containers (3) |
| api-gateway | 27 | 19 | · | 2 | — | wso2 api manager (14) · wso2 api control plane (11) · consul (8) |
| cloud-platform | 16 | 1 | · | 5 | — | swift (3) · plesk (2) · strands-agents-tools (2) |
| — | 10 | 3 | · | 3 | — | wso2 identity server as key manager (7) · wso2 open banking iam (7) · identity server as key manager (2) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification