Skip to content
Brief Security & Trust ·

AhnLab: 36,971 CVEs in Q3 2026, and 100 added to CISA's exploited list

AhnLab says attacks have widened beyond perimeter devices to internal systems that hold credentials and code.

In brief
  • AhnLab ASEC counted 36,971 CVEs in Q3 2026, about 78.6% more than in Q2. CISA added 100 flaws to its exploited list, double last year's 50.
  • Of the 100, 31 were web or server apps and 30 were network or perimeter devices. Six were AI tools.

AhnLab ASEC, a South Korean security team, published a 6 October report on the third quarter of 2026. It counted 36,971 new CVEs (public IDs for software flaws), about 78.6% more than in the second quarter. AhnLab said CISA, the US cyber agency, added 100 flaws to its exploited-bug list, double last year's 50 for the same months. Of those, 31 were web or server apps, 30 were network or perimeter devices, 9 were build and deploy tools, and 6 were AI tools.

AhnLab said attacks reached beyond edge devices; it reported real attacks on Gitea and SharePoint. A path traversal flaw in GitLab (reading files outside allowed folders) risks leaking source code and CI/CD secrets. An authentication bypass in Langflow risks admin access and theft of internal LLM API keys. On NetScaler and Cisco FMC, attackers hid web shells (remote-control scripts) as .Deb or CSS files. Neither report says how many organisations were breached or who was behind it.

AhnLab says exploitation has widened to internal systems holding credentials, secrets and code, while edge devices stay targets. Questions for the security lead: which admin consoles face the internet, how fast are listed flaws patched, who can reach CI/CD secrets?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: AhnLab ASEC, AhnLab ASEC, Wordfence.