Solution sectors / communications
Communications
Communication software — email servers and clients, messaging platforms, VoIP and video conferencing — carries sensitive conversations and is a frequent phishing and interception target. This hub tracks CVEs across it.
Cumulative CVEs
7,724
across 294 monthly snapshots
Latest month
95 · proj
-39.1% MoM · +63.8% YoY
Peak month
214
Jun 20
KEV this month
0
25 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem82%
- Mixed18%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Communications.
- CVE-2026-66141Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.7.4
- CVE-2026-66140Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.8.4
- CVE-2026-63765Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation8.2
- CVE-2026-44909Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WIND...7.5
- CVE-2026-59540WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability9.8
- CVE-2026-9729Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter6.4
- CVE-2026-61256Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Servers). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerab...6.3
- CVE-2026-60829Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploit...8.8
- CVE-2026-60491Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration). Supported versions that are affected are 12.2.3-12.2.15. Easily explo...6.3
- CVE-2026-16361Memory safety bugs fixed in Thunderbird ESR 140.139.8
- CVE-2026-16360Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 1539.8
- CVE-2026-16412Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 1539.8
- CVE-2026-16411Memory safety bugs fixed in Firefox 1539.8
- CVE-2026-16410JIT miscompilation in the JavaScript Engine: JIT component9.8
- CVE-2026-16409Invalid pointer in the Security: PSM component7.5
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| mattermost | 12 | · | · |
| eleveo | 10 | · | · |
| cyrusimap | 9 | · | · |
| astrbotdevs | 8 | · | · |
| roundcube | 6 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| messaging-chat | 39 | 1 | · | 11 | — | mattermost (12) · mattermost server (10) · astrbot (8) |
| email-server-client | 22 | · | · | 7 | — | cyrus imap (9) · webmail (6) · sendportal (2) |
| voip-telephony | 14 | · | · | 2 | — | call recording software (10) · switchvox smb edition (4) |
| — | 4 | · | · | 3 | — | anydesk (2) · imp (1) · rustdesk (1) |
| video-conferencing | 4 | · | · | 2 | — | bigbluebutton (3) · avideo (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification