Récap annuel
Sécurité des apps · 2026
Bilan 2026 indexé par Appaloosa Scout : 6 412 CVE publiées dans l'année sur les apps suivies, 25 ajoutées au catalogue CISA KEV (exploitées en réel), 6 apps affectées par au moins une KEV.
Voir les tendances pluriannuelles dans l'Observatoire des menaces
- CVE indexées dans l'année
- 6 412
- KEV CISA ajoutées
- 25
- Apps suivies touchées
- 6
Distribution par sévérité
CRITICAL
641
HIGH
3 462
MEDIUM
2 131
LOW
178
Top 10 KEV de l'année
Triées par sévérité CVSS. « Apps » compte les apps suivies du catalogue : beaucoup de KEV sont au niveau OS et affichent légitimement 0.
| CVE | Sévérité | Apps | Ajouté KEV | Description |
|---|---|---|---|---|
|
CVE-2025-39682
0 apps
|
CRITICAL 9.8 | 0 | 2026-09-18 | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg(… |
|
CVE-2026-33824
0 apps
|
CRITICAL 9.8 | 0 | 2026-08-18 | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-65400
0 apps
|
CRITICAL 9.8 | 0 | 2026-08-18 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, ma… |
|
CVE-2026-50522
0 apps
|
CRITICAL 9.8 | 0 | 2026-07-22 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-58644
0 apps
|
CRITICAL 9.8 | 0 | 2026-07-16 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-20963
0 apps
|
HIGH 9.8 | 0 | 2026-03-18 | Microsoft SharePoint Remote Code Execution Vulnerability |
|
CVE-2024-43468
0 apps
|
CRITICAL 9.8 | 0 | 2026-02-12 | Microsoft Configuration Manager Remote Code Execution Vulnerability |
|
CVE-2026-55040
0 apps
|
CRITICAL 9.1 | 0 | 2026-08-18 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2009-0238
3 apps
|
HIGH 8.8 | 3 | 2026-04-14 | Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Wor… |
|
CVE-2026-87491
2 apps
|
HIGH 8.8 | 2 | 2026-09-09 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox vi… |
Top vendors par KEV cette année
- 1 Google LLC 7 KEV · 1 apps
- 2 Microsoft 4 KEV · 1 apps
- 3 Microsoft Office 3 KEV · 1 apps
- 4 Microsoft Corporation 2 KEV · 2 apps
- 5 Adobe 2 KEV · 1 apps
- 6 Adobe Acrobat Reader 2 KEV · 1 apps
Apps les plus affectées
Google Chrome
winget:Google.Chrome
Aucune vuln. ouverte
Chrome
com.google.Chrome
Aucune vuln. ouverte
Office
winget:Microsoft.Office
Aucune vuln. ouverte
Microsoft Office
brew:cask:microsoft-office
Aucune vuln. ouverte
Adobe Acrobat Reader (64-bit)
winget:Adobe.Acrobat.Reader.64-bit
Aucune vuln. ouverte
Adobe Acrobat Reader
brew:cask:adobe-acrobat-reader
Aucune vuln. ouverte
Microsoft PowerPoint
com.microsoft.Powerpoint
Aucune vuln. ouverte
Microsoft Excel
com.microsoft.Excel
Aucune vuln. ouverte
Méthodologie
KEV : ajoutées au catalogue CISA durant l'année (kev_added_date). CVE : date de publication NVD. Apps : celles indexées dans Scout au moment de la requête, l'historique évolue à chaque nouvel ajout au catalogue.