Solution sectors / operating-systems
Operating Systems
Operating systems are the foundation of every device, which makes their vulnerabilities some of the most far-reaching. This hub tracks CVEs across Linux distributions, Windows, macOS, the BSDs and mobile operating systems.
Cumulative CVEs
71,307
across 299 monthly snapshots
Latest month
315 · proj
-84.2% MoM · -46.1% YoY
Peak month
2,693
May 26
KEV this month
0
10 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem83%
- Embedded10%
- Mixed7%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Operating Systems.
- CVE-2026-19548Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing5.5
- CVE-2026-18663389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control5.9
- CVE-2026-12235Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787)6.3
- CVE-2026-12234TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write7.8
- CVE-2026-12233Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention5.9
- CVE-2026-12232Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties6.1
- CVE-2026-19550Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes4.3
- CVE-2026-65680Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability6.7
- CVE-2026-62738Windows Management Instrumentation Information Disclosure Vulnerability5.5
- CVE-2026-62898Microsoft QUIC Information Disclosure Vulnerability7.5
- CVE-2026-71331Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability8.1
- CVE-2026-70354.NET Core Remote Code Execution Vulnerability7.8
- CVE-2026-63522Azure SQL Database Elevation of Privilege Vulnerability7.8
- CVE-2026-70337Microsoft PowerShell Remote Code Execution Vulnerability8.8
- CVE-2026-70338Microsoft PowerShell Security Feature Bypass Vulnerability7.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| linux | 46 | 3 | · |
| redhat | 44 | 2 | · |
| microsoft | 33 | 13 | · |
| qualcomm, inc. | 11 | 1 | · |
| zephyrproject | 8 | · | · |
| suse | 5 | 1 | · |
| openwrt | 4 | · | · |
| contiki-ng | 3 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| linux-distro | 88 | 3 | · | 5 | — | linux (46) · red hat enterprise linux 8 (27) · red hat enterprise linux 9 (27) |
| windows | 21 | 7 | · | 1 | — | edge chromium (14) · application insights profiler (1) · azure confidential ledger (1) |
| rtos-embedded-os | 11 | · | · | 2 | — | zephyr (8) · contiki-ng (3) |
| unix-bsd | 1 | · | · | 1 | — | macos (1) |
| mobile-os | 1 | 1 | · | 1 | — | android (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification