Security Products
Security products — endpoint protection, SIEM, identity and access management, scanners and PKI — are trusted with the keys to the kingdom, so their vulnerabilities are especially dangerous. This hub tracks CVEs across defensive tooling.
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem83%
- SaaS17%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Security Products.
- CVE-2026-76081ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions5.5
- CVE-2026-90942Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints9.6
- CVE-2026-55866SpiceDBChecks involving relations with caveats can result in unconditional permission when conditional permission is expected3.7
- CVE-2026-50157Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK6.5
- CVE-2026-59570Android ZCC denial of service7.5
- CVE-2026-59569Android ZCC VPN API method privilege escalation8.1
- CVE-2026-25687ZCC race condition in ZPA tunnel handler8.1
- CVE-2026-25832In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.3.7
- CVE-2025-26790Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.3.7
- CVE-2026-90485IOBit Uninstaller IOCTL Dispatch IURegistryFilter.sys sub_11838 null pointer dereference5.5
- CVE-2026-89298Keycloak-services: keycloak-services: confidential client secret disclosed to view-clients role via client registration get4.9
- CVE-2026-84390A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access ...9.8
- CVE-2026-88770Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-force-locked accounts6.5
- CVE-2026-19584Velociraptor VQL injection during notebook restore from backup7.7
- CVE-2026-19583Velociraptor Required Permissions bypass by using client monitoring queries9.9
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| misp | 27 | 3 | · |
| tanium | 21 | · | · |
| misp-project | 20 | 3 | · |
| okta | 17 | · | · |
| fortinet | 10 | 2 | · |
| ivanti | 10 | 6 | · |
| palo alto networks | 9 | · | · |
| nozomi networks | 5 | · | · |
| auth0 | 4 | 1 | · |
| configserver | 3 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| vuln-mgmt-scanner | 47 | 9 | · | 15 | — | misp (47) · cmc (5) · guardian (5) |
| — | 33 | 12 | · | 5 | — | neurons for itsm (5) · cloud ngfw (3) · configserver security & firewall (3) |
| identity-access-mgmt | 32 | 3 | · | 9 | — | okta access gateway (11) · red hat single sign-on 7 (4) · auth0 ad/ldap connector (3) |
| siem-soar | 21 | · | · | 2 | — | comply (16) · enforce (2) · st2 (2) |
| secure-gateway-vpn | 9 | 1 | · | 5 | — | endpoint dlp (3) · seppmail secure email gateway (seg) (2) · fortimonitoronsight (1) |
| endpoint-av-edr | 5 | · | · | 2 | — | manageengine endpoint central (4) · uninstaller (1) |
| pki-crypto | 1 | · | · | 1 | — | forge (1) |