2026 CVE Vulnerabilities
65,269 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-98164 | — | — | — | Sep 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address s... |
| CVE-2026-96869 | — | — | — | Sep 29, 2026 | Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and ... |
| CVE-2026-82973 | CRITICAL | 9.4 | — | Sep 29, 2026 | Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a r... |
| CVE-2026-82804 | — | — | — | Sep 29, 2026 | The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharac... |
| CVE-2026-7193 | HIGH | 8.6 | — | Sep 29, 2026 | A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attack... |
| CVE-2026-7192 | CRITICAL | 9.3 | — | Sep 29, 2026 | A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to... |
| CVE-2026-76875 | MEDIUM | 5.3 | — | Sep 29, 2026 | PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityP... |
| CVE-2026-76114 | MEDIUM | 5.9 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sen... |
| CVE-2026-73599 | MEDIUM | 5.4 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted... |
| CVE-2026-73598 | HIGH | 7.8 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignm... |
| CVE-2026-102437 | HIGH | 7.8 | — | Sep 29, 2026 | OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasoni... |
| CVE-2026-101271 | LOW | 2.1 | — | Sep 29, 2026 | OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) t... |
| CVE-2026-101270 | LOW | 2.1 | — | Sep 29, 2026 | Malicious HTML content could be injected into the help texts of various fields with organizer permissions. |
| CVE-2026-101269 | LOW | 2.3 | — | Sep 29, 2026 | The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same s... |
| CVE-2026-101268 | LOW | 1.7 | — | Sep 29, 2026 | If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's custo... |
| CVE-2026-101267 | LOW | 2.7 | — | Sep 29, 2026 | A missing permission check allowed low-privileged users with access to an event but without access to the event's orders... |
| CVE-2026-100832 | HIGH | 8.8 | — | Sep 29, 2026 | Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox ESR 115.4... |
| CVE-2026-100831 | HIGH | 8.8 | — | Sep 29, 2026 | Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and F... |
| CVE-2026-100830 | — | — | — | Sep 29, 2026 | Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100829 | — | — | — | Sep 29, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100828 | — | — | — | Sep 29, 2026 | Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 15... |
| CVE-2026-100826 | — | — | — | Sep 29, 2026 | Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefo... |
| CVE-2026-100825 | HIGH | 8.8 | — | Sep 29, 2026 | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 15... |
| CVE-2026-100824 | — | — | — | Sep 29, 2026 | Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100823 | — | — | — | Sep 29, 2026 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now