Solution sectors / consumer-software
Consumer Software
Consumer desktop software — browsers, media players, productivity apps and utilities — is installed on hundreds of millions of machines, making it a broad attack surface. This hub tracks CVEs across it.
Cumulative CVEs
24,806
across 294 monthly snapshots
Latest month
1,354 · proj
+31.1% MoM · +867.1% YoY
Peak month
1,401
Jun 26
KEV this month
8
31 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem96%
- Mixed4%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Consumer Software.
- CVE-2026-84518This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a us...4.3
- CVE-2026-55093tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load6.1
- CVE-2026-55832Tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx6.1
- CVE-2026-85892Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability7.8
- CVE-2026-90938LangBot through 0.4.17 Unauthenticated Plugin Registration via WebSocket8.6
- CVE-2026-90562LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key8.1
- CVE-2026-90493Tonec Internet Download Manager Kernel Driver idmwfp.sys access control8.8
- CVE-2026-90556Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load7.8
- CVE-2026-90557Freeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via Savegame6.1
- CVE-2026-77490Microsoft Edge (Chromium-based) Spoofing Vulnerability6.1
- CVE-2026-70341Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability8.5
- CVE-2026-88046rclone: source object names can escape the configured root on upload5.3
- CVE-2026-88045rclone: S3 multipart declared-length memory exhaustion7.5
- CVE-2026-88044rclone: RC per-server auth-proxy bypass9.1
- CVE-2026-88018rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass9.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| adobe | 170 | 7 | 1 |
| mozilla | 35 | 12 | · |
| siyuan-note | 23 | 1 | · |
| rclone | 9 | 2 | · |
| gnome | 5 | · | · |
| menulux software inc. | 4 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| productivity | 307 | 37 | 1 | 7 | — | microsoft 365 apps for enterprise (106) · 365 apps (105) · microsoft office 2019 (105) |
| browser | 299 | 53 | 2 | 3 | — | chrome (268) · firefox (29) · microsoft edge (chromium-based) (2) |
| — | 49 | 20 | 5 | 9 | — | visual studio code (12) · adobe commerce (9) · commerce (9) |
| file-utility | 15 | 2 | · | 7 | — | rclone (9) · convertx (1) · hp support assistant (1) |
| media-player | 4 | · | · | 3 | — | vlc media player (2) · mp3 audio player for music, radio & podcast by sonaar (1) · raw image extension (1) |
| gaming | 3 | · | · | 2 | — | freeciv (2) · nintendo switch (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification