Solution sectors / communications
Communications
Communication software — email servers and clients, messaging platforms, VoIP and video conferencing — carries sensitive conversations and is a frequent phishing and interception target. This hub tracks CVEs across it.
Cumulative CVEs
8,076
across 296 monthly snapshots
Latest month
120 · proj
-42.0% MoM · +135.3% YoY
Peak month
214
Jun 20
KEV this month
0
14 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Mixed59%
- On-prem41%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Communications.
- CVE-2026-91181Data Retention Teams Endpoint Leaks Private Team Invite ID6.5
- CVE-2026-12985Mattermost DCR redirect URI allowlist bypass via improper URL component validation6.8
- CVE-2026-82920Mattermost ABAC parent policy bypass via policy update endpoint5.5
- CVE-2026-86348MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process4.3
- CVE-2026-86349Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting4.3
- CVE-2026-7208Yealink SIP-T33G < 124.87.0.0 Race Condition via Diagnostic File Deletion5.3
- CVE-2026-10556Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.5.3
- CVE-2026-13417Boards plugin denial of service via unvalidated block fields.properties4.3
- CVE-2026-9812Missing property field ownership validation in Playbooks run property update endpoint6.5
- CVE-2026-8821Playbooks run owner channel membership permission bypass7.1
- CVE-2026-5132Unbounded zlib decompression in Calls SDP WebSocket messages6.5
- CVE-2026-15814Uploading a crafted image causes excessive memory allocation in the Mattermost Server6.5
- CVE-2026-10542Playbooks channel action update validation issue5.0
- CVE-2026-14344Inconsistent authorization checks in Mattermost Boards endpoints4.3
- CVE-2026-12882Mattermost Markdown autolink parsing denial of service4.3
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| email-server-client | 39 | 11 | · | 4 | — | thunderbird (31) · cyrus imap (6) · electerm (1) |
| voip-telephony | 15 | 4 | · | 5 | — | pjproject (8) · pjsip (8) · quality management (4) |
| messaging-chat | 6 | · | · | 5 | — | ai-infra-guard (1) · aig-skill-scan (1) · bp better messages (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification