[2026.04] Threat Intelligence Report | SECaaS Platform AIONCLOUD

Threat Intelligence Report

Get up-to-date information on web application vulnerabilities, attacks, and how to respond.

Back to Threat Intelligence Report

[2026.04] Threat Intelligence Report

Status of High-Risk Vulnerabilities

No. Vulnerability No. (CVE) Content CVSS Risk Level
1CVE-2026-20131Cisco Secure FMC Insecure Deserialization10CRITICAL
2CVE-2026-27897Vociferous Path Traversal10CRITICAL
3CVE-2026-32306OneUptime SQL Injection9.9CRITICAL
4CVE-2026-29058AVideo Encoder Command Injection9.8CRITICAL
5CVE-2026-31896WeGIA SQL Injection9.8CRITICAL
6CVE-2026-26793GL-iNet GL-AR300M16 Command Injection9.8CRITICAL
7CVE-2026-26795GL-iNet GL-AR300M16 Command Injection9.8CRITICAL
8CVE-2026-26791GL-iNet GL-AR300M16 Command Injection9.8CRITICAL
9CVE-2026-26792GL-iNet GL-AR300M16 Command Injection9.8CRITICAL
10CVE-2026-29183SiYuan Cross-Site Scripting9.3CRITICAL

Distribution of Web Application Attack Types

No. Attack Type % Key Features and Purpose
1SQL Injection42.5%Database manipulation, privilege escalation, and sensitive data exfiltration
2Application Vulnerability14.92%Exploitation of application-level flaws (insufficient authentication, misconfigurations)
3System File Access11.35%Unauthorized access attempts to internal server files and directories
4Default Page9.02%Collection of system information through exposure of default configuration pages
5Bad User-Agent7.7%Automated reconnaissance activities using malicious scanners or bots

Key Attack Detection Status by Industry

No. Industry Total First Attack Type Second Attack Type
1Education Industry3,970,000 casesSQL Injection ~1,720,000 casesApplication Vulnerability ~850,000 cases
2Service Industry3,280,000 casesSQL Injection ~1,730,000 casesApplication Vulnerability ~600,000 cases
3Manufacturing Industry1,940,000 casesDefault Page ~600,000 casesSystem File Access ~360,000 cases
4Public Institutions1,570,000 casesSQL Injection ~580,000 casesApplication Vulnerability ~320,000 cases





The Threat Intelligence Report provides the latest web vulnerability analyses, industry-specific attack patterns,
and key CVE-based vulnerability information, all based on processed data from the AI/ML-powered threat intelligence platform AILabs.

Subscribe to receive the full monthly Threat Intelligence Report!

[ Subscribe → ]
Scroll Up