Solution sectors / networking-infrastructure
Networking & Infrastructure
Routers, firewalls, VPN gateways and DNS servers sit at the edge of every network, so a single flaw can expose everything behind it. This hub follows CVE trends across network hardware and infrastructure software.
router-switch · 31load-balancer-proxy · 26firewall · 21network-management · 13vpn-gateway · 11dns-dhcp-ntp
Cumulative CVEs
27,784
across 297 monthly snapshots
Latest month
598 · proj
+9.1% MoM · +153.4% YoY
Peak month
791
May 26
KEV this month
10
46 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem82%
- Mixed10%
- Embedded8%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Networking & Infrastructure.
- CVE-2026-75945A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.2.6
- CVE-2026-75944A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User2.6
- CVE-2026-75943A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcem2.6
- CVE-2026-77191All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on an2.6
- CVE-2026-73449On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADI5.9
- CVE-2026-75792IBM Sterling Secure Proxy is vulnerable to multiple issues4.3
- CVE-2026-78415IBM Sterling Secure Proxy is vulnerable to multiple issues5.4
- CVE-2026-89021MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction6.9
- CVE-2026-89020MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path4.3
- CVE-2026-76442Cisco Secure Email Gateway Security Hardening Release7.5
- CVE-2026-76461Cisco Secure Email Gateway SQL Injection VulnerabilityKEV9.8
- CVE-2026-76443Cisco Secure Email Gateway Security Hardening Release9.8
- CVE-2026-76441Cisco Secure Email Gateway Security Hardening Release9.8
- CVE-2026-76440Cisco Secure Email Gateway Security Hardening Release9.8
- CVE-2026-20353Cisco Secure Email Gateway Security Hardening Release9.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| arubanetworks | 52 | 5 | · |
| oisf | 15 | 1 | · |
| traefik | 13 | 1 | · |
| cisco | 12 | 3 | · |
| tenda | 12 | 8 | · |
| strongswan | 11 | · | · |
| openvpn | 9 | · | · |
| d-link | 8 | 6 | · |
| tp-link systems inc. | 8 | · | · |
| f5 | 7 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| — | 197 | 36 | 8 | 12 | — | secure connect gateway (89) · fabric composer (52) · openvpn (8) |
| router-switch | 31 | 5 | 2 | 14 | — | routeros (6) · pfsense plus (3) · archer ax55 v4 (2) |
| load-balancer-proxy | 26 | 1 | · | 8 | — | traefik (13) · eclipse jetty (3) · nginx javascript (3) |
| firewall | 21 | 2 | · | 5 | — | suricata (15) · pfsense ce (3) · core (1) |
| network-management | 13 | 5 | · | 6 | — | freeipmi (6) · hpe icewall products (2) · netbox (2) |
| vpn-gateway | 11 | · | · | 1 | — | strongswan (11) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification