Solution sectors / communications
Communications
Communication software — email servers and clients, messaging platforms, VoIP and video conferencing — carries sensitive conversations and is a frequent phishing and interception target. This hub tracks CVEs across it.
Cumulative CVEs
7,831
across 295 monthly snapshots
Latest month
57 · proj
-66.1% MoM · +7.5% YoY
Peak month
214
Jun 20
KEV this month
0
9 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem67%
- SaaS33%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Communications.
- CVE-2026-73227electerm's RDP clipboard file download may parse unsafe file name8.1
- CVE-2026-73226Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist8.8
- CVE-2026-73225electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename8.1
- CVE-2026-73224Electerm check folder size function may get attacked by unsafe folder name8.8
- CVE-2026-73223electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename8.1
- CVE-2026-53416Zoom VDI - Path Traversal7.1
- CVE-2026-53415Zoom Clients - Use After Free8.3
- CVE-2026-53414Zoom Clients - Buffer Over-read6.5
- CVE-2026-53413Zoom Clients - Buffer Over-write8.3
- CVE-2026-72919Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams4.3
- CVE-2026-72918Rocket.Chat: Insecure implementation of websocket notifications5.4
- CVE-2026-72915Mastodon: Personally-identifying information disclosure due to incorrect access control validation7.5
- CVE-2026-72914Mastodon: Exhausting data by an unauthenticated request to the admin retention API7.5
- CVE-2026-72719Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter6.7
- CVE-2026-72578FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher8.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| opensips | 8 | 3 | · |
| misskey-dev | 5 | · | · |
| 2 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| messaging-chat | 13 | 2 | · | 7 | — | misskey (5) · teams (3) · element-call (1) |
| voip-telephony | 8 | 3 | · | 1 | — | opensips (8) |
| — | 1 | · | · | 1 | — | facebook for woocommerce (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification