Barbon Risk Index
The Barbon Risk Index is a continuous index of technology providers whose products were vulnerable to exploitation by threat actors. The ranking leverages public data, threat intelligence, and machine learning exploitability models to help underwriters, brokers, and enterprise security leaders make better-informed technology adoption and cyber risk decisions.
Empowered by the Barbon Exploit Scoring System (BESS)¹ & NIST CPE Dictionary
To create the Barbon Risk Index, we use the Barbon Exploit Scoring System (BESS)¹ to score vulnerabilities that appear in the National Institute of Standards and Technology's (NIST) Official Common Platform Enumeration (CPE) Dictionary. We map vulnerabilities from the National Vulnerability Database (NVD) to vendors using NIST enrichment, scoring vendors by adding up all of their vulnerabilities weighted by real-world exploitability over time.
Barbon Risk Index: Vendor Rankings
Showing tech providers mapped via NIST Common Platform Enumeration (CPE) weighted by exploit density.
| Vendor Name | |||
|---|---|---|---|
| 1. | MicrosoftTop Risk Operating System & Enterprise Software | 3,210 | 190.5 |
| 2. | AppleTop Risk Consumer & Enterprise Devices | 2,033 | 131.7 |
| 3. | LinuxTop Risk Kernel & Server Infrastructure | 6,654 | 113.9 |
| 4. | Google Browser & Cloud Ecosystem | 2,409 | 106.4 |
| 5. | Oracle Database & Middleware | 633 | 40.6 |
| 6. | Adobe Creative & PDF Productivity | 793 | 32.4 |
| 7. | Cisco Networking & Hardware | 311 | 30.1 |
| 8. | Tenda IoT & Consumer Networking | 660 | 29.5 |
| 9. | Apache Web Server & Open Source | 535 | 25.9 |
| 10. | Fortinet Network Security & Firewalls | 173 | 20.5 |
Barbon Risk Index Overview
A snapshot of the technology providers highlighted in the Barbon Risk Index and the vulnerabilities assessed across global commercial exposures.
Total number of vulnerabilities evaluated by Barbon in the Barbon Risk Index during the current 12-month review period.
Total number of commercial technology software and hardware vendors scored using NIST CPE enrichment algorithms.
How the Barbon Risk Index has evolved
Historical progression of tech risk vulnerability severity and vendor exploit density over the past 5 quarters (Q2 2025 – Q2 2026).
Average Vendor Score Over Time
In the past quarter, the average vendor score in the Barbon Risk Index increased 11%.
Contributing Vulnerabilities Over Time
In the past quarter, the number of contributing vulnerabilities in the Barbon Risk Index increased 18%.
¹ Barbon Inc., Barbon Exploit Scoring System Pat. No. US 12,028,359 B1 issued July 2, 2024
The Barbon Risk Index is based on publicly available data and is intended for general, informational purposes only, and not as legal, professional, or consulting advice; use of the Barbon Risk Index is solely at your own risk. The Barbon Risk Index is a list of unaffiliated third-party technology providers ranked by a methodology based on Barbon’s Exploit Scoring System (Barbon ESS), which is powered by generative AI, machine learning, and an underlying algorithm that provides assessment of all publicly disclosed vulnerabilities and evaluates a technology vendor's risk based on the exploitability of reported vulnerabilities over a set time period. Barbon disclaims all warranties, express or implied. Barbon Risk Index results may vary or fluctuate based on factors outside of Barbon's control.