Solution sectors / networking-infrastructure
Networking & Infrastructure
Routers, firewalls, VPN gateways and DNS servers sit at the edge of every network, so a single flaw can expose everything behind it. This hub follows CVE trends across network hardware and infrastructure software.
router-switch · 63network-management · 43load-balancer-proxy · 40dns-dhcp-ntp · 8firewall · 7vpn-gateway · 1
Cumulative CVEs
26,761
across 295 monthly snapshots
Latest month
304 · proj
-20.6% MoM · -6.5% YoY
Peak month
791
May 26
KEV this month
8
66 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem53%
- Embedded30%
- Mixed17%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Networking & Infrastructure.
- CVE-2026-66374Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.8.1
- CVE-2026-16764OWASP DefectDojo API/Web serializers.py UserSerializer privileges management6.3
- CVE-2026-637329router before 0.4.60 Remote Code Execution via default password9.9
- CVE-2026-633139Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch7.7
- CVE-2026-52688RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation7.5
- CVE-2026-52686Wildcard CNAME proof validation bypass3.7
- CVE-2026-52684Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack3.7
- CVE-2026-13321DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field8.6
- CVE-2026-13204Unexpected exit in certain situations with NSEC and NSEC3 both present7.5
- CVE-2026-12617Record ordering based unexpected exit with CNAME or DNAME7.5
- CVE-2026-11721Cache poisoning possible with label count discrepancy, RRSIG, and wildcards7.5
- CVE-2026-11622Potential memory usage beyond configured limits7.5
- CVE-2026-11605Unnecessary validation of DNSSEC signed records7.5
- CVE-2026-11331Potential wildcard CNAME RPZ policy bypass7.5
- CVE-2026-10822Key Record using PRIVATEDNS algorithm may lead to unexpected exit6.5
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| ubiquiti inc | 25 | 7 | · |
| ui | 25 | 7 | · |
| juniper | 22 | · | · |
| cisco | 19 | · | · |
| watchguard | 17 | · | · |
| decolua | 16 | 6 | · |
| f5 | 8 | · | · |
| h2o | 8 | · | · |
| shibby | 8 | · | · |
| tenda | 8 | 1 | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| — | 103 | 44 | 8 | 19 | — | junos os (18) · fireware os (17) · junos (15) |
| router-switch | 63 | 13 | · | 12 | — | 9router (16) · tomato (8) · be12 pro (6) |
| network-management | 43 | 29 | · | 12 | — | wireshark (12) · cloud gateways (7) · dream machines (7) |
| load-balancer-proxy | 40 | 6 | · | 11 | — | avi load balancer (7) · eclipse jetty (4) · h2o (4) |
| dns-dhcp-ntp | 8 | · | · | 6 | — | coredns (3) · adguardhome (1) · gpsd (1) |
| firewall | 7 | · | · | 5 | — | modsecurity (3) · bunkerweb (2) · stormshield network security (2) |
| vpn-gateway | 1 | · | · | 1 | — | access server (1) · openvpn access server (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification