Arc

  • New chat
  • Search chats
  • Projects
  • Artefacts

Starred

  • Weekly threat summary

Recent All chats

  • CVE severity trends
  • Supplier risk review
  • Board briefing draft
  • Policy translation
Threat Intel/CVE Severity Trends: Q2 vs Q3 2

/cve-triageCompare Critical and High CVEs for Q2 and Q3, and flag any Critical ones we’re exposed to. Output as .docx.

cve-q3-2026.csvvendor-advisories.pdfasset-inventory.xlsx

Critical disclosures rose to 41 in Q3, up from 26 in Q2, and have run above High every week since week 7’s vendor patch cycle. Two of the Critical CVEs affect products in your asset inventory:

CVEProductVectorStatus
2026-98417Ferncastle Forms pluginNetwork, auth requiredPatched
2026-98452Quillgate ProxyNetwork, no authAwaiting fix

Recommend prioritising CVE-2026-98452: no authentication required and no vendor patch yet. The full report is ready to review:

CVE Severity Trends: Q2 vs Q3 2026Document · .docx

Type a message…

Secure Select model

OverviewSearchFilesArtefacts

CVE Severity Trends: Q2 vs Q3 2026v1 of 1 · .docxShare

Critical CVEs up 58% on Q2: 41 in Q3 against 26, and above High every week since week 7

Weekly count of newly disclosed CVEs for widely deployed enterprise software in Q3 2026, by CVSS severity band, from the tracked advisory feed, with Q2 totals for comparison.

Critical vs High severity CVEs by week, Q3 2026

High (CVSS 7.0–8.9)Critical (CVSS 9.0–10.0)

02468Vendor patch cycleQ3 total: 41 CriticalW1W2W3W4W5W6W7W8W9W10W11W12W13

Reading the chart

  • Red = Critical (CVSS 9.0–10.0)
  • Amber = High (CVSS 7.0–8.9)
  • Scale is new disclosures per week; each point is that week’s total from the tracked feed.

What it shows

  • Week 7, vendor patch cycle: one widely deployed CMS platform’s disclosure round pushes Critical to 6 in a week, the quarter’s peak and its turning point.
  • Quarter close: 41 Critical in Q3 against 26 in Q2 (+58%), while High stays flat at 2 to 4 a week (40 in the quarter).