month report
May 2026
Data as of Jun 8, 2026, 05:00 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
May 2026 closed with 7,241 published CVEs — +66.0% YoY . 627 criticals, 21 added to CISA KEV (2 ransomware-linked). linux led volume, mostly via linux. Biggest breakout: google at ×8.8 their 12-month median. Top weakness class — CWE-79 (596 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
7,241
+12.5% MoM+66.0% YoY
Severity mix
627 / 2,624
critical / high
KEV added
21
2 ransomware-linked
Nuclei coverage
0.5%
33 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
9.4
n=22
Within 7 days
45.5%
Within 30 days
100.0%
Days → KEV (median)
0
n=15
Weakness × Vendor
What's spreading where in May 2026
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS89SQL Injection862Missing Authorization416Use After Free22Path Traversal78OS Command Injection94Code Injection77Command Injection918SSRF20Improper Input Validationlinux41google41129456microsoft5228423817apple1725apache software foundation424657npm343227apache424656openclaw16218edimax323open-webui815251openwebui815251red hat42
Breakout vendors
CVE count ≥3× their own 12-period median.
- 8.8×google381 CVE
- 7.9×edimax59 CVE
- 5.9×f553 CVE
- 5.1×concretecms36 CVE
- 4.7×helmholz42 CVE
- 4.7×mb connect line42 CVE
- 4.3×trendnet26 CVE
- 4.1×apache software foundation87 CVE
- 4.0×apache80 CVE
- 4.0×open5gs38 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #18concrete cms44 CVE
- #21open ises44 CVE
- #22helmholz42 CVE
- #23mb connect line42 CVE
- #27concretecms36 CVE
- #32netatalk33 CVE
- #41trendnet26 CVE
- #46budibase21 CVE
- #54joomla20 CVE
- #55joomla! project20 CVE
Top vendors
Ranked by distinct CVE count this period.
- 1,034 CVE43 critCVSS 6.7linux (1034) · linux kernel (573)
- 381 CVE13 critCVSS 7.0×8.8chrome (373) · android (7) · mcp toolbox for databases (1)
- 171 CVE24 critCVSS 7.5KEV 3windows server 2025 (server core installation) (65) · windows server 2025 (65) · windows 11 version 24h2 (60)
- 100 CVECVSS 6.8macos (91) · ipados (70) · iphone os (70)
- 87 CVE19 critCVSS 7.3×4.1apache ofbiz (17) · apache http server (11) · apache cloudstack (7)
- 86 CVEopenclaw (33) · flowise (15) · @hulumi/policies (4)
- 80 CVE18 critCVSS 7.3×4.0ofbiz (17) · http server (11) · tomcat (7)
- 75 CVE8 critCVSS 7.1openclaw (70) · crabbox (5)
- 59 CVECVSS 7.8×7.9ew-7438rpn (24) · br-6675nd (12) · br-6478ac (11)
- 59 CVE1 critCVSS 6.6Nuclei 2open-webui (59)
- 59 CVE1 critCVSS 6.6Nuclei 2open webui (59)
- 57 CVE3 critCVSS 7.0red hat enterprise linux 9 (24) · red hat enterprise linux 10 (24) · red hat enterprise linux 8 (23)
- 53 CVE1 critCVSS 7.1×5.9big-ip (44) · big-iq (9) · nginx open source (7)
- 51 CVE2 critCVSS 6.9commerce b2b (15) · adobe commerce (15) · commerce (15)
- 50 CVE31 critCVSS 8.8a8000ru (26) · ca750-poe (9) · n300rh (7)
- 49 CVECVSS 7.8×3.3amd ryzen™ embedded 8000 series processors (18) · amd ryzen™ 8040 series mobile processors with radeon™ graphics (formerly codenamed "hawk point") (12) · amd ryzen™ 7035 series processors with radeon™ graphics (formerly codenamed "rembrandt r") (12)
- 49 CVE6 critCVSS 6.9http server (8) · db2 (6) · aspera high-speed transfer endpoint (4)
- 44 CVECVSS 7.0NEWconcrete cms (44)
- 44 CVEgix (4) · imageproc (3) · astral-tokio-tar (3)
- 44 CVE9 critCVSS 8.1firefox (43) · thunderbird (37) · firefox for ios (2)
- 44 CVECVSS 6.4NEWtickets (37) · open ises project (7)
- 42 CVECVSS 6.6NEW×4.7myrex24v2 (40) · myrex24v2.virtual (40) · rex100 (2)
- 42 CVECVSS 6.6NEW×4.7mbconnect24 (40) · mymbconnect24 (40) · mbnet/mbnet.rokey (2)
- 41 CVEgithub.com/lin-snow/ech0 (7) · github.com/kong/kubernetes-ingress-controller/v3 (2) · github.com/caddyserver/caddy/v2 (2)
- 38 CVECVSS 4.5×4.0open5gs (38)
- 37 CVECVSS 7.3PoC 1stigmem-node (6) · wger (4) · edumfa (3)
- 36 CVECVSS 7.0NEW×5.1concrete cms (36)
- 36 CVECVSS 5.1×3.8mattermost (36) · mattermost server (24) · mattermost desktop (2)
- 36 CVE1 critCVSS 9.1thorsten/phpmyfaq (17) · phpmyfaq/phpmyfaq (17) · azuracast/azuracast (3)
- 34 CVE1 critCVSS 6.6build of keycloak (24) · enterprise linux (10) · openshift container platform (7)
- 34 CVECVSS 5.8hospitals patient records management system (6) · sup online shopping (5) · indian invoicing system (4)
- 33 CVE1 critCVSS 5.8NEWnetatalk (33)
- 33 CVE1 critCVSS 7.1tesla (12) · geforce (12) · nvidia rtx, quadro, nvs (12)
- 32 CVECVSS 7.1×3.2hpe aruba networking wireless operating system (aos) (27) · arubaos (aos) (5)
- 32 CVE9 critCVSS 7.7oracle rest data services (10) · oracle payroll (3) · oracle database server (3)
- 31 CVECVSS 5.6gitlab (31)
- 31 CVE9 critCVSS 7.7rest data services (10) · e-business suite (7) · database server (3)
- 30 CVE8 critCVSS 7.2×3.2crypto (13) · go (11) · net (6)
- 27 CVECVSS 7.1arubaos (27) · sd-wan (26)
- 27 CVE2 critCVSS 9.4×3.9KEV 2Nuclei 1PoC 27prisma access (9) · cloud ngfw (9) · pan-os (9)
- 26 CVECVSS 7.1NEW×4.3tew-432brp (20) · tew-821dap firmware (6) · tew-821dap (6)
- 24 CVECVSS 4.3aion (9) · bigfix service management (sm) (8) · dfxanalytics (5)
- 23 CVECVSS 5.9employee management system (9) · online hospital management system (3) · online music site (2)
- 22 CVECVSS 5.9teamcity (12) · youtrack (5) · intellij idea (4)
- 22 CVECVSS 5.8avideo (22)
- 21 CVE2 critCVSS 7.7NEW×3.0budibase (21)
- 21 CVE1 critCVSS 6.1powerflex manager (rack) (8) · powerflex manager (8) · powerflex manager (appliance) (8)
- 21 CVECVSS 5.0bigfix service management (14) · dfxanalytics (5) · bigfix webui application administration (2)
- 21 CVE6 critCVSS 7.7KEV 1PoC 1simatic s7-1500 cpu 1516f-3 pn/dp (4) · simatic s7-1500 cpu 1516-3 pn/dp (4) · simatic s7-1500 cpu 1515f-2 pn (4)
- 20 CVE2 critCVSS 6.8KEV 1Nuclei 1PoC 20cisco catalyst sd-wan manager (4) · cisco iot field network director (iot-fnd) (3) · cisco identity services engine software (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | linux | 1,034 | 43 | · | · | linux (1034) · linux kernel (573) | · | ||
| 2 | 381 | 13 | · | · | ×8.8 | chrome (373) · android (7) · mcp toolbox for databases (1) | ↑3 | ||
| 3 | microsoft | 171 | 24 | 3 | · | KEV 3 | windows server 2025 (server core installation) (65) · windows server 2025 (65) · windows 11 version 24h2 (60) | · | |
| 4 | apple | 100 | · | · | · | macos (91) · ipados (70) · iphone os (70) | ↑65 | ||
| 5 | apache software foundation | 87 | 19 | · | · | ×4.1 | apache ofbiz (17) · apache http server (11) · apache cloudstack (7) | ↑7 | |
| 6 | npm | 86 | · | · | · | openclaw (33) · flowise (15) · @hulumi/policies (4) | ↓4 | ||
| 7 | apache | 80 | 18 | · | · | ×4.0 | ofbiz (17) · http server (11) · tomcat (7) | ↑7 | |
| 8 | openclaw | 75 | 8 | · | · | openclaw (70) · crabbox (5) | ↓4 | ||
| 9 | edimax | 59 | · | · | · | ×7.9 | ew-7438rpn (24) · br-6675nd (12) · br-6478ac (11) | — | |
| 10 | open-webui | 59 | 1 | · | 2 | Nuclei 2 | open-webui (59) | — | |
| 11 | openwebui | 59 | 1 | · | 2 | Nuclei 2 | open webui (59) | — | |
| 12 | red hat | 57 | 3 | · | · | red hat enterprise linux 9 (24) · red hat enterprise linux 10 (24) · red hat enterprise linux 8 (23) | ↑3 | ||
| 13 | f5 | 53 | 1 | · | · | ×5.9 | big-ip (44) · big-iq (9) · nginx open source (7) | — | |
| 14 | adobe | 51 | 2 | · | · | commerce b2b (15) · adobe commerce (15) · commerce (15) | ↑5 | ||
| 15 | totolink | 50 | 31 | · | · | a8000ru (26) · ca750-poe (9) · n300rh (7) | ↓6 | ||
| 16 | amd | 49 | · | · | · | ×3.3 | amd ryzen™ embedded 8000 series processors (18) · amd ryzen™ 8040 series mobile processors with radeon™ graphics (formerly codenamed "hawk point") (12) · amd ryzen™ 7035 series processors with radeon™ graphics (formerly codenamed "rembrandt r") (12) | — | |
| 17 | ibm | 49 | 6 | · | · | http server (8) · db2 (6) · aspera high-speed transfer endpoint (4) | ↑8 | ||
| 18 | concrete cms | 44 | · | · | · | NEW | concrete cms (44) | — | |
| 19 | crates.io | 44 | · | · | · | gix (4) · imageproc (3) · astral-tokio-tar (3) | ↑40 | ||
| 20 | mozilla | 44 | 9 | · | · | firefox (43) · thunderbird (37) · firefox for ios (2) | ↑3 | ||
| 21 | open ises | 44 | · | · | · | NEW | tickets (37) · open ises project (7) | — | |
| 22 | helmholz | 42 | · | · | · | NEW×4.7 | myrex24v2 (40) · myrex24v2.virtual (40) · rex100 (2) | — | |
| 23 | mb connect line | 42 | · | · | · | NEW×4.7 | mbconnect24 (40) · mymbconnect24 (40) · mbnet/mbnet.rokey (2) | — | |
| 24 | go | 41 | · | · | · | github.com/lin-snow/ech0 (7) · github.com/kong/kubernetes-ingress-controller/v3 (2) · github.com/caddyserver/caddy/v2 (2) | ↓8 | ||
| 25 | open5gs | 38 | · | · | · | ×4.0 | open5gs (38) | — | |
| 26 | pypi | 37 | · | · | · | PoC 1 | stigmem-node (6) · wger (4) · edumfa (3) | ↓9 | |
| 27 | concretecms | 36 | · | · | · | NEW×5.1 | concrete cms (36) | — | |
| 28 | mattermost | 36 | · | · | · | ×3.8 | mattermost (36) · mattermost server (24) · mattermost desktop (2) | ↑127 | |
| 29 | packagist | 36 | 1 | · | · | thorsten/phpmyfaq (17) · phpmyfaq/phpmyfaq (17) · azuracast/azuracast (3) | ↓11 | ||
| 30 | redhat | 34 | 1 | · | · | build of keycloak (24) · enterprise linux (10) · openshift container platform (7) | ↓6 | ||
| 31 | sourcecodester | 34 | · | · | · | hospitals patient records management system (6) · sup online shopping (5) · indian invoicing system (4) | ↓10 | ||
| 32 | netatalk | 33 | 1 | · | · | NEW | netatalk (33) | — | |
| 33 | nvidia | 33 | 1 | · | · | tesla (12) · geforce (12) · nvidia rtx, quadro, nvs (12) | ↑47 | ||
| 34 | hewlett packard enterprise (hpe) | 32 | · | · | · | ×3.2 | hpe aruba networking wireless operating system (aos) (27) · arubaos (aos) (5) | — | |
| 35 | oracle corporation | 32 | 9 | · | · | oracle rest data services (10) · oracle payroll (3) · oracle database server (3) | ↓28 | ||
| 36 | gitlab | 31 | · | · | · | gitlab (31) | ↑13 | ||
| 37 | oracle | 31 | 9 | · | · | rest data services (10) · e-business suite (7) · database server (3) | ↓29 | ||
| 38 | golang | 30 | 8 | · | · | ×3.2 | crypto (13) · go (11) · net (6) | ↑51 | |
| 39 | arubanetworks | 27 | · | · | · | arubaos (27) · sd-wan (26) | — | ||
| 40 | palo alto networks | 27 | 2 | 2 | 1 | ×3.9KEV 2Nuclei 1PoC 27 | prisma access (9) · cloud ngfw (9) · pan-os (9) | — | |
| 41 | trendnet | 26 | · | · | · | NEW×4.3 | tew-432brp (20) · tew-821dap firmware (6) · tew-821dap (6) | ↑134 | |
| 42 | hcl | 24 | · | · | · | aion (9) · bigfix service management (sm) (8) · dfxanalytics (5) | — | ||
| 43 | code-projects | 23 | · | · | · | employee management system (9) · online hospital management system (3) · online music site (2) | ↓33 | ||
| 44 | jetbrains | 22 | · | · | · | teamcity (12) · youtrack (5) · intellij idea (4) | — | ||
| 45 | wwbn | 22 | · | · | · | avideo (22) | ↓7 | ||
| 46 | budibase | 21 | 2 | · | · | NEW×3.0 | budibase (21) | ↑117 | |
| 47 | dell | 21 | 1 | · | · | powerflex manager (rack) (8) · powerflex manager (8) · powerflex manager (appliance) (8) | ↓21 | ||
| 48 | hcltech | 21 | · | · | · | bigfix service management (14) · dfxanalytics (5) · bigfix webui application administration (2) | — | ||
| 49 | siemens | 21 | 6 | 1 | · | KEV 1PoC 1 | simatic s7-1500 cpu 1516f-3 pn/dp (4) · simatic s7-1500 cpu 1516-3 pn/dp (4) · simatic s7-1500 cpu 1515f-2 pn (4) | ↑123 | |
| 50 | cisco | 20 | 2 | 1 | 1 | KEV 1Nuclei 1PoC 20 | cisco catalyst sd-wan manager (4) · cisco iot field network director (iot-fnd) (3) · cisco identity services engine software (2) | ↓14 |
Top weaknesses
CWE classes by distinct CVE count.