Récap annuel
Sécurité mobile · 2026
Bilan 2026 indexé par Appaloosa Scout : 1 927 CVE mobile publiées dans l'année, 18 ajoutées au catalogue CISA KEV (exploitées en réel), 0 apps mobiles affectées par au moins une KEV.
Voir les tendances pluriannuelles dans l'Observatoire des menaces
- CVE indexées dans l'année
- 1 927
- KEV CISA ajoutées
- 18
- Apps suivies touchées
- 0
Distribution par sévérité
CRITICAL
204
HIGH
1 183
MEDIUM
510
LOW
30
Top 10 KEV mobiles de l'année
Trié par nombre d'apps mobiles affectées (CVSS en départage).
| CVE | Sévérité | Apps | Ajouté KEV | Description |
|---|---|---|---|---|
|
CVE-2026-50522
0 apps
|
CRITICAL 9.8 | 0 | 2026-07-22 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-58644
0 apps
|
CRITICAL 9.8 | 0 | 2026-07-16 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-20963
0 apps
|
HIGH 9.8 | 0 | 2026-03-18 | Microsoft SharePoint Remote Code Execution Vulnerability |
|
CVE-2024-43468
0 apps
|
CRITICAL 9.8 | 0 | 2026-02-12 | Microsoft Configuration Manager Remote Code Execution Vulnerability |
|
CVE-2026-45659
0 apps
|
HIGH 8.8 | 0 | 2026-07-01 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
|
CVE-2026-11645
0 apps
|
HIGH 8.8 | 0 | 2026-06-09 | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sa… |
|
CVE-2023-21529
0 apps
|
HIGH 8.8 | 0 | 2026-04-13 | Microsoft Exchange Server Remote Code Execution Vulnerability |
|
CVE-2026-5281
0 apps
|
HIGH 8.8 | 0 | 2026-04-01 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execu… |
|
CVE-2025-31277
0 apps
|
HIGH 8.8 | 0 | 2026-03-20 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tv… |
|
CVE-2026-3909
0 apps
|
HIGH 8.8 | 0 | 2026-03-13 | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a … |
Méthodologie
KEV : ajoutées au catalogue CISA durant l'année (kev_added_date). CVE : date de publication NVD. Apps : celles indexées dans Scout au moment de la requête — l'historique évolue à chaque nouvel ajout au catalogue.