Security Products
Security products — endpoint protection, SIEM, identity and access management, scanners and PKI — are trusted with the keys to the kingdom, so their vulnerabilities are especially dangerous. This hub tracks CVEs across defensive tooling.
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem49%
- Embedded24%
- Mixed17%
- SaaS5%
- Library4%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Security Products.
- CVE-2026-65711sysPass 3.2.11 Authenticated OS Command Injection via Backup Path7.2
- CVE-2026-65710sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption7.1
- CVE-2026-65709sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API8.3
- CVE-2026-65708sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController8.1
- CVE-2026-17059Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter6.5
- CVE-2026-17048Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api5.5
- CVE-2026-14172Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation7.8
- CVE-2026-15981SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter9.8
- CVE-2026-21655C-CURE 9000 and Victor application server - Deserialization of Untrusted Data8.8
- CVE-2026-59545WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authentication vulnerability8.1
- CVE-2026-60455Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.8
- CVE-2026-60439Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.8
- CVE-2026-61246Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.8
- CVE-2026-60371Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.0
- CVE-2026-60373Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| openclaw | 44 | · | · |
| palo alto networks | 14 | 1 | · |
| paloaltonetworks | 14 | 1 | · |
| sipeed | 13 | · | · |
| absolute | 12 | · | · |
| fortinet | 12 | · | · |
| wireshark | 12 | · | · |
| absolute security | 11 | · | · |
| zitadel | 9 | · | · |
| trustedfirmware | 8 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| identity-access-mgmt | 52 | 10 | · | 16 | — | red hat single sign-on 7 (13) · zitadel (9) · privileged remote access (4) |
| — | 46 | 5 | · | 8 | — | pan-os (20) · cloud ngfw (11) · wireshark (11) |
| vuln-mgmt-scanner | 28 | 1 | · | 14 | — | cmc (10) · clamav (7) · guardian (5) |
| endpoint-av-edr | 24 | · | · | 7 | — | secure access (23) · msteams (3) · osquery (3) |
| siem-soar | 17 | 1 | · | 9 | — | wazuh (7) · opencti (4) · thehive (2) |
| pki-crypto | 15 | 1 | · | 3 | — | op-tee (8) · sigstore-js (4) · bc-lts (1) |
| secure-gateway-vpn | 13 | · | · | 7 | — | libreswan (6) · guardian (5) · wso2 universal gateway (2) |