Q3 2026 Vulnerability Trend Report
Summary of Vulnerability Trends for the Third Quarter of 2026
A total of 36,971 CVEs were disclosed in the third quarter of 2026, representing an increase of approximately 78.6% Compared to the second quarter. Among the vulnerabilities for which CVSS assessments were completed, approximately 12.7% Were rated “Critical” and approximately 42.6% Were rated “High,” meaning that more than half of the assessed vulnerabilities were classified as high-risk. By vulnerability type, CWE-284 (Improper Access Control) was the most common with 2,712 instances, followed by CWE-79 (XSS) and CWE-862 (Missing Authorization).
One hundred new vulnerabilities were added to the CISA KEV (Known Exploited Vulnerabilities) catalog in the third quarter. Of these, 58 were rated “Critical” with a CVSS score of 9.0 Or higher, accounting for approximately 58% of the total. Actual exploitation expanded beyond network and security equipment to include collaboration platforms, file-sharing solutions, source code management systems, and AI and machine learning operational tools.
Key Attack Trends
Threat actors intensively exploited vulnerabilities related to missing authentication, improper authentication, insufficient access control, command and code injection, path traversal, deserialization, and file uploading. In particular, externally exposed management interfaces and API endpoints were exploited as primary points of entry. Actual exploitation cases were identified in product families such as SharePoint, PaperCut, Gitea, WSO2, Adobe Commerce, Cisco ISE, and Check Point.
Major Vulnerability Cases
- CVE-2026-50522 A deserialization vulnerability (the process of converting untrusted data into objects) in Microsoft SharePoint that allows an unauthenticated remote threat actor to perform arbitrary code execution. On-premises SharePoint servers exposed to the internet were the primary targets.
- CVE-2026-16812 A command injection vulnerability in Arista VeloCloud Orchestrator that allows a threat actor to perform arbitrary OS command execution with root privileges.
- CVE-2026-76460 An API authentication bypass vulnerability in the Cisco Identity Service Engine that allows an unauthenticated threat actor to bypass administrator authentication.
- CVE-2026-85102 A certificate validation flaw in the Check Point Quantum Security Gateway allowed remote code execution without authentication.
- CVE-2026-5430 An authentication bypass vulnerability in WSO2 API Platform Products that could lead to the compromise of administrator accounts via a tampered JWT.
- CVE-2026-59310 A directory traversal vulnerability in Broadcom VMware vCenter Server allowed arbitrary code execution on the host system.
- CVE-2026-85706 A path traversal vulnerability in GitLab CE/EE allowed access to local files on the server, posing a risk of source code, database account, and CI/CD secret leaks.
- CVE-2026-88771 A lack of input validation in Citrix NetScaler ADC/Gateway allowed for remote code execution without authentication.
- CVE-2026-9198 A authentication bypass vulnerability in IBM Langflow OSS posed a risk of gaining administrator privileges, remote code execution, and internal LLM API key theft and credential theft for the vector DB.
- CVE-2026-84869 Inadequate privilege management in ConnectWise ScreenConnect allowed for the transmission and execution of arbitrary files through active sessions.
Severity and Impact
This quarter, the attack surface expanded to include not only existing external perimeter devices but also internal core infrastructure such as AI workflow platforms, API management systems, collaboration platforms, virtualization management servers, and development repositories. In particular, vulnerabilities confirmed to have been actively exploited showed a pattern where attack code was developed shortly after disclosure, leading to large-scale scanning campaigns. As a result, there were concerns about damage such as remote code execution, administrator privilege escalation, intrusion into internal networks, credential leakage, and loss of control over virtualization infrastructure.
Response Strategies
The report proposed the following key response measures: identifying externally exposed assets, applying Vulnerability Patches based on vulnerability prioritization, conducting breach trace inspections, and minimizing account and API permissions. It also summarized the need to continuously monitor whether administrator consoles, virtualization servers, API endpoints, and AI development platforms are exposed to the internet; implement multi-factor authentication (MFA); and verify system logs before and after patching, as well as check for any unauthorized sessions.