Solution sectors / operating-systems
Operating Systems
Operating systems are the foundation of every device, which makes their vulnerabilities some of the most far-reaching. This hub tracks CVEs across Linux distributions, Windows, macOS, the BSDs and mobile operating systems.
Cumulative CVEs
70,352
across 298 monthly snapshots
Latest month
1,327 · proj
+10.5% MoM · +46.1% YoY
Peak month
2,693
May 26
KEV this month
15
26 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem95%
- Mixed3%
- Embedded2%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Operating Systems.
- CVE-2026-10681SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot6.5
- CVE-2026-66337Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until()6.5
- CVE-2026-66338Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked()5.4
- CVE-2026-66339Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels6.5
- CVE-2026-17039Pki-core: dogtag-pki: redhat-pki: pki-core: ca renewal request processing omits realm authorization check performed by enrollment path3.1
- CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability10.0
- CVE-2026-17059Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter6.5
- CVE-2026-7007Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image4.6
- CVE-2026-17048Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api5.5
- CVE-2026-16743Accountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed users5.5
- CVE-2026-16730Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup5.5
- CVE-2026-58275Azure DNS Elevation of Privilege Vulnerability10.0
- CVE-2026-62825Azure Key Vault Elevation of Privilege Vulnerability10.0
- CVE-2026-35425Azure API Management (APIM) Remote Code Execution Vulnerability8.0
- CVE-2026-56160Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability9.1
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| microsoft | 645 | 23 | 3 |
| linux | 472 | 2 | · |
| redhat | 65 | 4 | · |
| samsung mobile | 18 | · | · |
| zephyrproject | 15 | · | · |
| qualcomm, inc. | 11 | · | · |
| openbsd | 8 | · | · |
| openwrt | 8 | 1 | · |
| op-tee | 8 | · | · |
| suse | 8 | 1 | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| linux-distro | 555 | 18 | · | 12 | — | linux (472) · red hat enterprise linux 8 (28) · red hat enterprise linux 9 (28) |
| windows | 509 | 198 | 15 | 2 | — | windows server 2025 (388) · windows server 2025 (server core installation) (388) · windows 11 version 26h1 (382) |
| unix-bsd | 32 | 2 | · | 3 | — | data domain operating system (25) · libxfont2 (3) · illumos-gate (2) |
| rtos-embedded-os | 28 | · | · | 5 | — | zephyr (15) · optee_os (8) · qnx os for medical (3) |
| mobile-os | 27 | · | · | 2 | — | samsung mobile devices (13) · harmonyos (8) · emui (4) |
| — | 5 | 1 | · | 2 | — | microsoft exchange server 2016 cumulative update 23 (4) · i (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification