Skip to main content
BARBON RISK INDEX • 2026 EDITION

Barbon Risk Index

The Barbon Risk Index is a continuous index of technology providers whose products were vulnerable to exploitation by threat actors. The ranking leverages public data, threat intelligence, and machine learning exploitability models to help underwriters, brokers, and enterprise security leaders make better-informed technology adoption and cyber risk decisions.

How the Barbon Risk Index was created

Empowered by the Barbon Exploit Scoring System (BESS)¹ & NIST CPE Dictionary

To create the Barbon Risk Index, we use the Barbon Exploit Scoring System (BESS)¹ to score vulnerabilities that appear in the National Institute of Standards and Technology's (NIST) Official Common Platform Enumeration (CPE) Dictionary. We map vulnerabilities from the National Vulnerability Database (NVD) to vendors using NIST enrichment, scoring vendors by adding up all of their vulnerabilities weighted by real-world exploitability over time.

Full Methodology

Barbon Risk Index: Vendor Rankings

Showing tech providers mapped via NIST Common Platform Enumeration (CPE) weighted by exploit density.

Vendor Name
1.
MicrosoftTop Risk
Operating System & Enterprise Software
3,210190.5
2.
AppleTop Risk
Consumer & Enterprise Devices
2,033131.7
3.
LinuxTop Risk
Kernel & Server Infrastructure
6,654113.9
4.
Google
Browser & Cloud Ecosystem
2,409106.4
5.
Oracle
Database & Middleware
63340.6
6.
Adobe
Creative & PDF Productivity
79332.4
7.
Cisco
Networking & Hardware
31130.1
8.
Tenda
IoT & Consumer Networking
66029.5
9.
Apache
Web Server & Open Source
53525.9
10.
Fortinet
Network Security & Firewalls
17320.5
Showing 10 of 20 ranked vendors
Overview & Key Metrics

Barbon Risk Index Overview

A snapshot of the technology providers highlighted in the Barbon Risk Index and the vulnerabilities assessed across global commercial exposures.

Contributing Vulnerabilities
58,098

Total number of vulnerabilities evaluated by Barbon in the Barbon Risk Index during the current 12-month review period.

Quarterly Growth Rate+18% vs previous quarter
Total Vendors Scored
10,530

Total number of commercial technology software and hardware vendors scored using NIST CPE enrichment algorithms.

Average Vendor Score Increase+11% score increase
Quarterly Trends & Analytics

How the Barbon Risk Index has evolved

Historical progression of tech risk vulnerability severity and vendor exploit density over the past 5 quarters (Q2 2025 – Q2 2026).

Average Vendor Score Over Time

In the past quarter, the average vendor score in the Barbon Risk Index increased 11%.

+11% Q/Q

Contributing Vulnerabilities Over Time

In the past quarter, the number of contributing vulnerabilities in the Barbon Risk Index increased 18%.

+18% Q/Q

¹ Barbon Inc., Barbon Exploit Scoring System Pat. No. US 12,028,359 B1 issued July 2, 2024

The Barbon Risk Index is based on publicly available data and is intended for general, informational purposes only, and not as legal, professional, or consulting advice; use of the Barbon Risk Index is solely at your own risk. The Barbon Risk Index is a list of unaffiliated third-party technology providers ranked by a methodology based on Barbon’s Exploit Scoring System (Barbon ESS), which is powered by generative AI, machine learning, and an underlying algorithm that provides assessment of all publicly disclosed vulnerabilities and evaluates a technology vendor's risk based on the exploitability of reported vulnerabilities over a set time period. Barbon disclaims all warranties, express or implied. Barbon Risk Index results may vary or fluctuate based on factors outside of Barbon's control.

Barbon Technology Risk PlatformTerms of UsePrivacy PolicyAdditional Research & Reports