2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97395 | — | — | — | Sep 29, 2026 | Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set Fil... |
| CVE-2026-86450 | HIGH | 7.5 | — | Sep 29, 2026 | Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix... |
| CVE-2026-81569 | — | — | — | Sep 29, 2026 | An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not... |
| CVE-2026-78214 | — | — | — | Sep 29, 2026 | An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whethe... |
| CVE-2026-71899 | — | — | — | Sep 29, 2026 | A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The AP... |
| CVE-2026-71898 | — | — | — | Sep 29, 2026 | An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a... |
| CVE-2026-71897 | — | — | — | Sep 29, 2026 | An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-... |
| CVE-2026-4034 | HIGH | 8.7 | — | Sep 29, 2026 | Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially c... |
| CVE-2026-102521 | HIGH | 8.6 | — | Sep 29, 2026 | The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into reading more than it should from a buffer. ... |
| CVE-2026-102360 | HIGH | 8.6 | — | Sep 29, 2026 | A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, le... |
| CVE-2026-98164 | — | — | — | Sep 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address s... |
| CVE-2026-96869 | — | — | — | Sep 29, 2026 | Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and ... |
| CVE-2026-82973 | CRITICAL | 9.4 | — | Sep 29, 2026 | Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a r... |
| CVE-2026-82804 | — | — | — | Sep 29, 2026 | The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharac... |
| CVE-2026-7193 | HIGH | 8.6 | — | Sep 29, 2026 | A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attack... |
| CVE-2026-7192 | CRITICAL | 9.3 | — | Sep 29, 2026 | A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to... |
| CVE-2026-76875 | MEDIUM | 5.3 | — | Sep 29, 2026 | PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityP... |
| CVE-2026-76114 | MEDIUM | 5.9 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sen... |
| CVE-2026-73599 | MEDIUM | 5.4 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted... |
| CVE-2026-73598 | HIGH | 7.8 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignm... |
| CVE-2026-102437 | HIGH | 7.8 | — | Sep 29, 2026 | OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasoni... |
| CVE-2026-101271 | LOW | 2.1 | — | Sep 29, 2026 | OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) t... |
| CVE-2026-101270 | LOW | 2.1 | — | Sep 29, 2026 | Malicious HTML content could be injected into the help texts of various fields with organizer permissions. |
| CVE-2026-101269 | LOW | 2.3 | — | Sep 29, 2026 | The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same s... |
| CVE-2026-101268 | LOW | 1.7 | — | Sep 29, 2026 | If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's custo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now