Solution sectors / security-products
Security Products
Security products — endpoint protection, SIEM, identity and access management, scanners and PKI — are trusted with the keys to the kingdom, so their vulnerabilities are especially dangerous. This hub tracks CVEs across defensive tooling.
pki-crypto · 35identity-access-mgmt · 32secure-gateway-vpn · 13vuln-mgmt-scanner · 11endpoint-av-edr · 6siem-soar · 6
Cumulative CVEs
16,014
across 294 monthly snapshots
Latest month
274 · proj
-18.5% MoM · +156.1% YoY
Peak month
449
Mar 26
KEV this month
0
28 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem100%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Security Products.
- CVE-2026-70468A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1...8.1
- CVE-2026-26035An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12...9.8
- CVE-2026-70466A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all v...5.3
- CVE-2026-70467A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions,...3.8
- CVE-2026-71407A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute...5.6
- CVE-2026-71408A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of serv...5.3
- CVE-2026-70465A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unaut...8.1
- CVE-2026-11325cloudflare/pages-action is deprecated — migration required by September 18th, 20268.8
- CVE-2026-18652Velociraptor STACK Type Download Path Bypasses Denied Prefix Check4.9
- CVE-2026-64951Velociraptor DoS triggered by Divide by Zero panic3.5
- CVE-2026-64952Velociraptor Hunt Deletion With Insufficient Permission Check6.5
- CVE-2026-64955Velociraptor CSV Formula Injection in Export Pipeline6.1
- CVE-2026-64954Velociraptor collect_client() Permissions Bypass8.2
- CVE-2026-14180Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap5.3
- CVE-2026-18639Velociraptor OIDC Authenticator susceptible to email spoofing7.3
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| pki-crypto | 35 | · | · | 2 | — | bc-java (32) · bc-lts-java (28) · bc-fja (25) |
| identity-access-mgmt | 32 | 3 | · | 6 | — | red hat single sign-on 7 (13) · wso2 identity server (12) · red hat build of keycloak 26.6 (7) |
| secure-gateway-vpn | 13 | 5 | · | 3 | — | wso2 universal gateway (11) · frontmcp (1) · wireguard.sys (1) |
| vuln-mgmt-scanner | 11 | 2 | · | 7 | — | catchpulse (3) · openmanage server administrator (2) · qradar (2) |
| endpoint-av-edr | 6 | 1 | · | 5 | — | papercut ng/mf (2) · antivirus (1) · jingyun antivirus (1) |
| siem-soar | 6 | 1 | · | 2 | — | cti-transmute (4) · wazuh (2) |
| — | 3 | 1 | · | 3 | — | multi-domain security management server (1) · operation and maintenance security management system (1) · security management server (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification