Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-126
Weakness type CWE-126 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 118 | 97 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▂▁▂▁▃▅▅█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 3 · 2026-03 0 · 2026-04 4 · 2026-05 1 · 2026-06 11 · 2026-07 22 · 2026-08 21 · 2026-09 35 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-38172 | 7.5 | 79.7 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
| CVE-2024-43475 | 7.3 | 78.0 | — | Microsoft Windows Admin Center Information Disclosure Vulnerability |
| CVE-2025-26664 | 6.5 | 77.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2025-26672 | 6.5 | 77.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2026-44185 | 7.3 | 77.1 | — | Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` |
| CVE-2023-21701 | 7.5 | 75.7 | — | Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnera… |
| CVE-2023-21811 | 7.5 | 75.7 | — | Windows iSCSI Service Denial of Service Vulnerability |
| CVE-2023-21813 | 7.5 | 75.7 | — | Windows Secure Channel Denial of Service Vulnerability |
| CVE-2025-21203 | 6.5 | 75.4 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2025-26676 | 6.5 | 75.0 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2026-20846 | 7.5 | 72.0 | — | GDI+ Denial of Service Vulnerability |
| CVE-2024-38265 | 8.8 | 71.9 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2023-21720 | 5.3 | 67.6 | — | Microsoft Edge (Chromium-based) Tampering Vulnerability |
| CVE-2026-66312 | 8.8 | 64.5 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-72932 | 7.5 | 62.4 | — | Windows Message Queuing Queue Manager Information Disclosure Vulnerability |
| CVE-2024-43595 | 6.5 | 62.1 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-26155 | 6.5 | 61.4 | — | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
| CVE-2026-50468 | 6.5 | 61.4 | — | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67390 | 6.5 | 61.4 | — | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67393 | 6.5 | 61.4 | — | Microsoft SQL Server Information Disclosure Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 67 |
| qualcomm | 8 |
| red hat | 5 |
| wireshark foundation | 5 |
| apache | 3 |
| gnome | 3 |
| eclipse foundation | 2 |
| fortinet | 2 |
| rti | 2 |
| silabs.com | 2 |
| cisco | 1 |
| cyrusimap | 1 |
| gnu | 1 |
| libgit2 | 1 |
| libvips | 1 |