2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73263 | CRITICAL | 9.9 | — | Aug 12, 2026 | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_conte... |
| CVE-2026-50561 | CRITICAL | 9.4 | — | Aug 12, 2026 | Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version ... |
| CVE-2026-67285 | CRITICAL | 9.2 | — | Aug 12, 2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An u... |
| CVE-2026-26035 | CRITICAL | 9.8 | — | Aug 12, 2026 | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.... |
| CVE-2026-67282 | CRITICAL | 10 | — | Aug 12, 2026 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker ... |
| CVE-2026-66659 | CRITICAL | 9.3 | — | Aug 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome ... |
| CVE-2026-72526 | CRITICAL | 9.9 | — | Aug 12, 2026 | A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-man... |
| CVE-2026-70398 | CRITICAL | 9.6 | — | Aug 12, 2026 | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerabil... |
| CVE-2026-68067 | CRITICAL | 9.8 | — | Aug 11, 2026 | The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active... |
| CVE-2026-67568 | CRITICAL | 9.3 | — | Aug 11, 2026 | The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from int... |
| CVE-2026-5917 | CRITICAL | 9.6 | — | Aug 11, 2026 | libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command inj... |
| CVE-2026-66147 | CRITICAL | 9.4 | 1.0% | Aug 11, 2026 | An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier... |
| CVE-2026-48765 | CRITICAL | 9.9 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspa... |
| CVE-2026-73034 | CRITICAL | 9.8 | — | Aug 11, 2026 | DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary f... |
| CVE-2026-73032 | CRITICAL | 9.6 | — | Aug 11, 2026 | PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav... |
| CVE-2026-66145 | CRITICAL | 9.1 | 0.4% | Aug 11, 2026 | An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version... |
| CVE-2026-45618 | CRITICAL | 10 | — | Aug 11, 2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit... |
| CVE-2026-16230 | CRITICAL | 9.8 | — | Aug 11, 2026 | The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali... |
| CVE-2026-18691 | CRITICAL | 9 | — | Aug 11, 2026 | An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc... |
| CVE-2026-73211 | CRITICAL | 9.8 | — | Aug 11, 2026 | PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolat... |
| CVE-2026-73090 | CRITICAL | 9.3 | — | Aug 11, 2026 | PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVi... |
| CVE-2026-71398 | CRITICAL | 10 | — | Aug 11, 2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code... |
| CVE-2026-71362 | CRITICAL | 9.1 | — | Aug 11, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att... |
| CVE-2026-69102 | CRITICAL | 9.8 | — | Aug 11, 2026 | MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.proper... |
| CVE-2026-48381 | CRITICAL | 9 | — | Aug 11, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now