2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97395 | — | — | — | Sep 29, 2026 | Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set Fil... |
| CVE-2026-81569 | — | — | — | Sep 29, 2026 | An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not... |
| CVE-2026-78214 | — | — | — | Sep 29, 2026 | An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whethe... |
| CVE-2026-71899 | — | — | — | Sep 29, 2026 | A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The AP... |
| CVE-2026-71898 | — | — | — | Sep 29, 2026 | An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a... |
| CVE-2026-71897 | — | — | — | Sep 29, 2026 | An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-... |
| CVE-2026-98164 | — | — | — | Sep 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address s... |
| CVE-2026-96869 | — | — | — | Sep 29, 2026 | Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and ... |
| CVE-2026-82804 | — | — | — | Sep 29, 2026 | The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharac... |
| CVE-2026-100830 | — | — | — | Sep 29, 2026 | Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100829 | — | — | — | Sep 29, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100828 | — | — | — | Sep 29, 2026 | Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 15... |
| CVE-2026-100823 | — | — | — | Sep 29, 2026 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100822 | — | — | — | Sep 29, 2026 | Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100821 | — | — | — | Sep 29, 2026 | Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 15... |
| CVE-2026-100819 | — | — | — | Sep 29, 2026 | Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR ... |
| CVE-2026-100817 | — | — | — | Sep 29, 2026 | Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100816 | — | — | — | Sep 29, 2026 | Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157... |
| CVE-2026-100815 | — | — | — | Sep 29, 2026 | Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4 and Firef... |
| CVE-2026-100814 | — | — | — | Sep 29, 2026 | Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4... |
| CVE-2026-100813 | — | — | — | Sep 29, 2026 | Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100812 | — | — | — | Sep 29, 2026 | Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100811 | — | — | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.... |
| CVE-2026-100810 | — | — | — | Sep 29, 2026 | Other issue in the DevTools component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100809 | — | — | — | Sep 29, 2026 | Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now