# CVSS 10.0 Vendor Ranking: Who Ships the Most Critical Vulnerabilities in 2026? > A ranked table of 12 major enterprise infrastructure vendors by CVSS 10.0 vulnerability count and confirmed exploitability through September 2026, with Cisco's record advisory cluster and board-ready framing for CISOs. Source: https://playciso.com/blog/cvss-10-vendor-ranking-exploitability-2026 · Published: 2026-09-17 · Publisher: PlayCISO (https://playciso.com) --- When a CVSS 10.0 hits your infrastructure — like [CVE-2026-76460 in Cisco ISE](/blog/cve-2026-76460-cisco-ise-cvss-10-auth-bypass-active-exploitation) this week — the immediate question is "are we patched?" The board question that follows is harder: **which vendors in our stack consistently ship the worst-class vulnerabilities, and how often are those actually exploited?** This is the data for that conversation. ## Cisco's September 2026 advisory cluster: the trigger On September 16, 2026, Cisco published **77 new CVEs** in a single advisory cycle. The numbers are unusual by any vendor's standards: - 41 CVEs affect Identity Services Engine (ISE) — the network access policy engine - 28 CVEs affect Secure Firewall - 14 entries scored CVSS 10.0, the maximum possible severity The CVSS 10.0 entries span multiple product lines: CVEProductCVSSType **CVE-2026-76460**Cisco ISE / ISE-PIC10.0Auth bypass → root RCE ([actively exploited](/blog/cve-2026-76460-cisco-ise-cvss-10-auth-bypass-active-exploitation)) CVE-2026-20030Cisco ISE10.0SQL injection CVE-2026-20357Cisco ISE10.0Authentication bypass CVE-2026-20358Cisco ISE10.0Authentication bypass CVE-2026-20131Secure Firewall Management Center10.0SQL injection → RCE _Crosswork Network Controller — 9 separate flaws at CVSS 10.0_ _Secure Workload — 2 flaws at CVSS 10.0_ This is not a normal advisory cycle. For context, the average across all vendors from 2017 to 2023 was roughly **40 CVSS 10.0 entries per year, total, across all vendors combined**. Cisco alone contributed 14 in a single September release. And 2024 had already broken the pattern with 231 CVSS 10.0 entries industry-wide — a number 2026 is on pace to exceed. ## Vendor ranking: CVSS 10.0 vulnerabilities by count and exploitability The table below ranks 12 major enterprise infrastructure vendors by their cumulative CVSS 10.0 CVE count through September 2026, alongside their total CVE volume (all severities, 1999–2026), confirmed-exploited count (entries in CISA's Known Exploited Vulnerabilities catalog or with documented in-the-wild exploitation), and an exploitability level assessment. RankVendorTotal CVEs (All Severities)CVSS 10.0 CVEsConfirmed Exploited (KEV / ITW)Exploitability 1**Microsoft**27,09085+40+ in CISA KEV**Critical** 2**Oracle**12,98970+15+ in KEV**High** 3**Cisco**6,84455+30+ in KEV (13 in 2026)**Critical** 4**Adobe**7,83850+25+ in KEV**Critical** 5**Apache (OSS)**4,200+40+Log4Shell, Struts, others**Critical** 6**Google**16,88030+Chrome/Android in KEV**High** 7**Apple**15,51825+iOS/macOS zero-days**High** 8**Linux Kernel**19,93120+Privilege escalation chains**Moderate** 9**IBM**8,98018+Low-Moderate**Moderate** 10**Fortinet**1,200+15+FortiOS actively targeted**Critical** 11**VMware / Broadcom**1,100+10+ESXi ransomware campaigns**Critical** 12**Palo Alto Networks**600+8+PAN-OS zero-days 2024–2026**High** ## How to read this table **Total CVEs** is the vendor's cumulative count across all severities from 1999 through September 2026, per NIST NVD and MITRE data. **CVSS 10.0 CVEs** is the subset that scored the maximum severity. **Confirmed Exploited** reflects entries in CISA's Known Exploited Vulnerabilities (KEV) catalog or with documented in-the-wild (ITW) exploitation. **Exploitability** is an editorial assessment combining three factors: - How many CVSS 10.0 CVEs the vendor has accumulated - What proportion are confirmed exploited - How commonly the vendor's products sit in internet-facing or critical-path positions ## Three things that stand out ### 1. Cisco's 2026 is historically exceptional 13 actively exploited CVEs in a single year, 55+ lifetime CVSS 10.0 entries, and a single September advisory that contributed 14 CVSS 10.0 entries across ISE, Crosswork, Secure Firewall, and Secure Workload. For an organization running Cisco infrastructure, the patch load this year is qualitatively different from prior years. ### 2. Network infrastructure vendors carry disproportionate exploitation rates Cisco (6,844 total CVEs), Fortinet (1,200+), and Palo Alto Networks (600+) have far fewer total CVEs than Microsoft, Google, or Linux Kernel — but their CVSS 10.0 entries are exploited at significantly higher rates. The reason is architectural: these products sit at the network perimeter where they are directly reachable by attackers, and compromising them often bypasses endpoint security entirely. A CVSS 10.0 in a firewall or NAC appliance is not the same risk as a CVSS 10.0 in a desktop application, even if the score is identical. ### 3. Total CVE count alone is the wrong metric Linux Kernel has ~20,000 CVEs — more than any vendor except Microsoft. But its CVSS 10.0 count (20+) and exploitation rate are far lower than Fortinet, which has one-sixteenth the total CVEs but weaponized 10.0s showing up in ransomware campaigns. CVE volume correlates with codebase size and disclosure transparency, not with risk. Using it as a proxy for vendor security leads boards to the wrong conversation. ## For the board conversation If you are a CISO presenting this data, the framing matters more than the numbers. Here is what the board actually needs to understand: - The question is not "how many CVEs does vendor X have." It is: "what is our exposure to the vendors that generate the most exploited critical-class vulnerabilities, and how fast are we patching them?" - Vendor risk is not hypothetical. CVE-2026-76460 — a CVSS 10.0 auth bypass in the system that controls network access — went from disclosure to active exploitation to a three-day CISA federal deadline in a single day. The interval between "vendor publishes advisory" and "attacker uses it against you" is now measured in hours, not weeks. - Patch velocity is the metric that matters. The vendors at the top of this table are not going to stop shipping critical vulnerabilities. The differentiator is how fast your organization applies the fix once it exists. A CISO whose team consistently patches critical-class CVEs within 72 hours turns this table into a process confirmation. A CISO whose team measures patch cycles in weeks turns it into an active risk register. - This is a recurring conversation, not a one-time brief. The 2024 spike to 231 CVSS 10.0 entries across all vendors (up from ~40/year average) was not an anomaly — 2026 is on pace to exceed it. The board should expect this data on a quarterly cadence, not only when something makes the news. ## Explore the data interactively This ranking is also available as a **[free interactive tool](/tools/vendor-risk)** where you can filter by year, vendor category, and exploitability level, expand any vendor for year-over-year CVSS 10.0 trends and notable CVEs, and export the full dataset as CSV for board decks or risk registers. ## Assess your own posture PlayCISO's [Security Readiness Scorecard](/tools/scorecard) includes patch-management posture and vendor-risk assessment as scored dimensions. If you want to see where your organization stands on the practices that determine whether a CVSS 10.0 is a fire drill or a routine patch cycle, it takes two minutes and no signup. For a deeper exercise, PlayCISO's [Threat Model Generator](/tools/threat-model) can map your specific vendor stack against known attack patterns, and the [War Room simulations](/arcade) let your team practice the incident-response workflow for exactly this scenario: a critical infrastructure vulnerability under active exploitation with a 72-hour remediation window. ## Frequently asked questions **Which vendor has the most CVSS 10.0 vulnerabilities?** Based on cumulative CVE data through September 2026, Microsoft leads with 85+ CVSS 10.0 entries, followed by Oracle (70+), Cisco (55+), Adobe (50+), and Apache/open-source projects (40+). However, total count does not equal risk — network infrastructure vendors like Cisco, Fortinet, and Palo Alto Networks have disproportionately high exploitation rates because their products sit at the network perimeter. **What happened in Cisco's September 2026 advisory cycle?** Cisco published 77 new CVEs in a single advisory cycle. Of those, 41 affect ISE and 28 affect Secure Firewall. The cluster includes 14 CVSS 10.0 entries across ISE (including CVE-2026-76460), Crosswork Network Controller (9 at 10.0), Secure Firewall Management Center, and Secure Workload. **How is exploitability level determined?** It is an editorial assessment combining three factors: how many CVSS 10.0 CVEs the vendor has accumulated, what proportion have confirmed in-the-wild exploitation or appear in CISA's KEV catalog, and how commonly the vendor's products sit in internet-facing or critical-path positions where attackers can reach them directly. **Why is total CVE count misleading for vendor risk?** CVE volume correlates with codebase size and disclosure transparency more than with actual risk. The Linux Kernel has ~20,000 CVEs but far fewer CVSS 10.0 entries and a lower exploitation rate than vendors with one-third the count. A vendor with 1,200 total CVEs but 15 CVSS 10.0s that are actively exploited presents more immediate risk than one with 20,000 CVEs that are rarely weaponized at the 10.0 level. **How should a CISO present this to a board?** Frame it around exposure, not raw count. The board question is not "how many CVEs does vendor X have" but "what is our exposure to the vendors that generate the most exploited critical-class vulnerabilities, and how fast are we patching them." The vendor ranking table in this post is built for exactly that conversation.