Annual recap
Mobile security · 2026
2026 review indexed by Appaloosa Scout: 1,927 mobile CVE published, 18 added to the CISA KEV catalog (exploited in real attacks), 0 mobile apps affected by at least one KEV.
- CVE indexed this year
- 1,927
- CISA KEV added
- 18
- Tracked apps affected
- 0
Severity distribution
CRITICAL
204
HIGH
1,183
MEDIUM
510
LOW
30
Top 10 mobile KEV of the year
Sorted by number of mobile apps affected (CVSS as tiebreaker).
| CVE | Severity | Apps | Added to KEV | Description |
|---|---|---|---|---|
|
CVE-2026-50522
0 apps
|
CRITICAL 9.8 | 0 | 2026-07-22 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-58644
0 apps
|
CRITICAL 9.8 | 0 | 2026-07-16 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-20963
0 apps
|
HIGH 9.8 | 0 | 2026-03-18 | Microsoft SharePoint Remote Code Execution Vulnerability |
|
CVE-2024-43468
0 apps
|
CRITICAL 9.8 | 0 | 2026-02-12 | Microsoft Configuration Manager Remote Code Execution Vulnerability |
|
CVE-2026-45659
0 apps
|
HIGH 8.8 | 0 | 2026-07-01 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
|
CVE-2026-11645
0 apps
|
HIGH 8.8 | 0 | 2026-06-09 | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sa… |
|
CVE-2023-21529
0 apps
|
HIGH 8.8 | 0 | 2026-04-13 | Microsoft Exchange Server Remote Code Execution Vulnerability |
|
CVE-2026-5281
0 apps
|
HIGH 8.8 | 0 | 2026-04-01 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execu… |
|
CVE-2025-31277
0 apps
|
HIGH 8.8 | 0 | 2026-03-20 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tv… |
|
CVE-2026-3909
0 apps
|
HIGH 8.8 | 0 | 2026-03-13 | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a … |
Methodology
KEV: added to the CISA catalog during the year (kev_added_date). CVE: NVD publication date. Apps: those indexed in Scout at query time; the history evolves as new mappings are added.