Skip to content
Appaloosa Scout
Language selector
fr en

Annual recap

App security · 2026

2026 recap indexed by Appaloosa Scout: 6,419 CVEs published during the year on tracked apps, 25 added to the CISA KEV catalog (exploited in the wild), 6 apps affected by at least one KEV.

See multi-year trends in the Threat Observatory

CVE indexed this year
6,419
CISA KEV added
25
Tracked apps affected
6

Severity distribution

CRITICAL 633
HIGH 3,435
MEDIUM 2,173
LOW 178

Top 10 KEVs of the year

Sorted by CVSS severity. “Apps” counts tracked catalog apps: many KEVs are OS-level and legitimately show 0.

CVE Severity
CVE-2025-39682
0 apps
CRITICAL 9.8
CVE-2026-33824
0 apps
CRITICAL 9.8
CVE-2026-65400
0 apps
CRITICAL 9.8
CVE-2026-50522
0 apps
CRITICAL 9.8
CVE-2026-58644
0 apps
CRITICAL 9.8
CVE-2026-20963
0 apps
HIGH 9.8
CVE-2024-43468
0 apps
CRITICAL 9.8
CVE-2026-55040
0 apps
CRITICAL 9.1
CVE-2009-0238
3 apps
HIGH 8.8
CVE-2026-87491
2 apps
HIGH 8.8

Top vendors by KEV this year

  1. 1 Google LLC 7 KEV · 1 apps
  2. 2 Microsoft 4 KEV · 1 apps
  3. 3 Microsoft Office 3 KEV · 1 apps
  4. 4 Microsoft Corporation 2 KEV · 2 apps
  5. 5 Adobe 2 KEV · 1 apps
  6. 6 Adobe Acrobat Reader 2 KEV · 1 apps

Most affected apps

Methodology

KEV: added to the CISA catalog during the year (kev_added_date). CVE: NVD publication date. Apps: those indexed in Scout at query time; the history evolves as new mappings are added.