Tracked vendors, 2026
Distinct CVEs affecting security products. Routing, collaboration and other non-security lines are excluded — see methodology.
2026 to date
688
2025 same date
461
Pace
+49.2%
Known exploited
29
Severity, 2026
How serious this year's disclosures are.
- Critical 89 12.9%
- High 201 29.2%
- Medium 358 52.0%
- Low 39 5.7%
- Unscored 1 0.1%
Table view
| Vendor | Critical | High | Medium | Low | Unscored | Total |
|---|---|---|---|---|---|---|
| Cisco | 65 | 156 | 235 | 7 | 1 | 464 |
| Fortinet | 12 | 17 | 68 | 14 | 0 | 111 |
| Palo Alto Networks | 2 | 20 | 50 | 18 | 0 | 90 |
| Check Point | 8 | 7 | 3 | 0 | 0 | 18 |
| All | 89 | 201 | 358 | 39 | 1 | 688 |
A CVE affecting two vendors counts once under each, so the rows sum to more than the total.
Recently exploited in the wild
Added to the CISA KEV catalog — confirmed exploitation, not just severity.
| CVE | Published | Severity | Vendor | Products | EPSS |
|---|---|---|---|---|---|
| CVE-2026-104286 KEV | Oct 1, 2026 | Critical 9.8 Remote · no auth | fortinet | fortinet-fortimail | 0.022 |
| CVE-2026-76504 KEV | Sep 30, 2026 | Critical 9.8 Remote · no auth | cisco | cisco-sd-wan-manager | 0.016 |
| CVE-2026-93616 KEV | Sep 22, 2026 | Critical 9.8 Remote · no auth | check-point | check-point-security-management | 0.197 |
| CVE-2026-85102 KEV | Sep 9, 2026 | Critical 9.8 Remote · no auth | check-point | check-point-quantum-gateway | 0.075 |
| CVE-2026-76460 KEV | Sep 16, 2026 | Critical 10 Remote · no auth | cisco | cisco-ise, cisco-ise-pic | 0.140 |
Latest disclosures
Newest CVEs affecting tracked vendors.
| CVE | Published | Severity | Vendor | Products | EPSS |
|---|---|---|---|---|---|
| CVE-2026-104286 KEV | Oct 1, 2026 | Critical 9.8 Remote · no auth | fortinet | fortinet-fortimail | 0.022 |
| CVE-2026-76504 KEV | Sep 30, 2026 | Critical 9.8 Remote · no auth | cisco | cisco-sd-wan-manager | 0.016 |
| CVE-2026-84388 | Sep 22, 2026 | Critical 9.1 | fortinet | fortinet-fortipam | 0.004 |
| CVE-2026-93616 KEV | Sep 22, 2026 | Critical 9.8 Remote · no auth | check-point | check-point-security-management | 0.197 |
| CVE-2026-76426 | Sep 16, 2026 | Medium 4.9 | cisco | cisco-ise, cisco-ise-pic | 0.005 |
| CVE-2026-20121 | Sep 16, 2026 | Medium 5.3 Remote · no auth | cisco | cisco-asa, cisco-ftd | 0.005 |
| CVE-2026-76431 | Sep 16, 2026 | Medium 4.9 | cisco | cisco-ise, cisco-ise-pic | 0.012 |
| CVE-2026-76427 | Sep 16, 2026 | Medium 4.9 | cisco | cisco-ise, cisco-ise-pic | 0.005 |
| CVE-2026-76447 | Sep 16, 2026 | Medium 5.3 Remote · no auth | cisco | cisco-ise, cisco-ise-pic | 0.004 |
| CVE-2026-20285 | Sep 16, 2026 | Medium 4.3 | cisco | cisco-ise, cisco-ise-pic | 0.004 |
| CVE-2026-20287 | Sep 16, 2026 | Medium 6.5 | cisco | cisco-ise, cisco-ise-pic | 0.002 |
| CVE-2026-20286 | Sep 16, 2026 | Medium 4.3 | cisco | cisco-ise | 0.004 |
| CVE-2026-76438 | Sep 16, 2026 | Medium 6.5 | cisco | cisco-broadworks | 0.006 |
| CVE-2026-20072 | Sep 16, 2026 | Medium 4.9 | cisco | cisco-ise | 0.004 |
| CVE-2026-76446 | Sep 16, 2026 | Medium 4.9 | cisco | cisco-ise, cisco-ise-pic | 0.003 |