2026 CVE Vulnerabilities

57,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58123CRITICAL9.8Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attacker...
CVE-2026-58122CRITICAL9.3Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attacker...
CVE-2026-57054MEDIUM6.9A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS o...
CVE-2026-57032HIGH7.1An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Jun...
CVE-2026-57031MEDIUM4.7An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper N...
CVE-2026-57030HIGH8.2A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packe...
CVE-2026-57029MEDIUM6A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series...
CVE-2026-57028HIGH7.3An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve...
CVE-2026-57027HIGH7.1A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Netw...
CVE-2026-57026HIGH8.7An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on...
CVE-2026-57025MEDIUM6.8A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and...
CVE-2026-57024MEDIUM6.9A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos O...
CVE-2026-57023HIGH8.7An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS...
CVE-2026-57022HIGH8.2An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper N...
CVE-2026-57021MEDIUM6.9An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows ...
CVE-2026-57020HIGH7.1An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper N...
CVE-2026-57019HIGH7.1An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Net...
CVE-2026-55689HIGH8.1OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skippe...
CVE-2026-55605MEDIUM5.3DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hos...
CVE-2026-55604HIGH8.6DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-...
CVE-2026-55424MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured ...
CVE-2026-55170MEDIUM5.4OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the dat...
CVE-2026-53963CRITICAL9Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second...
CVE-2026-53962MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG s...
CVE-2026-53961MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now