Solution sectors / networking-infrastructure
Networking & Infrastructure
Routers, firewalls, VPN gateways and DNS servers sit at the edge of every network, so a single flaw can expose everything behind it. This hub follows CVE trends across network hardware and infrastructure software.
Cumulative CVEs
27,069
across 296 monthly snapshots
Latest month
341 · proj
-22.7% MoM · +7.2% YoY
Peak month
791
May 26
KEV this month
0
26 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Embedded46%
- On-prem45%
- Mixed9%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Networking & Infrastructure.
- CVE-2026-65941WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.8.8
- CVE-2026-65940WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.6.8
- CVE-2026-65939WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.6.8
- CVE-2026-65938WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.4.3
- CVE-2026-65937WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI8.0
- CVE-2026-66150Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restri...7.8
- CVE-2026-66149Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restri...7.8
- CVE-2026-18634An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to in...8.4
- CVE-2026-66154An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack...8.3
- CVE-2026-66148An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute sy...6.3
- CVE-2026-66147An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution throu...9.4
- CVE-2026-66146Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.6.1
- CVE-2026-66145An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary f...9.1
- CVE-2026-73216coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity6.5
- CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service VulnerabilityKEV8.6
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| cisco | 30 | 5 | · |
| d-link corporation | 15 | 15 | · |
| gl.inet | 11 | 5 | · |
| tp-link systems inc. | 10 | · | · |
| h3c | 8 | · | · |
| tp-link | 8 | · | · |
| tp link systems inc. | 6 | · | · |
| zte | 6 | · | · |
| gl-inet | 5 | 5 | · |
| traefik | 5 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| — | 62 | 15 | · | 10 | — | cisco ios xe software (12) · gl-mt3000 (8) · cisco secure endpoint (7) |
| router-switch | 52 | 20 | · | 11 | — | dwr-m961 (15) · nx15 (8) · omada access points (7) |
| load-balancer-proxy | 17 | 7 | · | 4 | — | wso2 traffic manager (11) · traefik (5) · eclipse jetty (1) |
| network-management | 1 | · | · | 1 | — | flowintel (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification