2026 CVE Vulnerabilities

43,872 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-55814HIGH7.5Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version ...
CVE-2026-55799CRITICAL9.8Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgra...
CVE-2026-44416CRITICAL9.8Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. U...
CVE-2026-42537CRITICAL9.8Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0...
CVE-2026-40920CRITICAL9.8Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade...
CVE-2026-32227CRITICAL9.8SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to v...
CVE-2026-28672CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. Thi...
CVE-2026-66915CRITICAL10Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute ar...
CVE-2026-44630HIGH7.5Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to caus...
CVE-2026-19404MEDIUM6.5A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati...
CVE-2026-66411MEDIUM6.9DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut...
CVE-2026-66410MEDIUM4.8Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or alt...
CVE-2026-66409MEDIUM6.9DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password ma...
CVE-2026-66408MEDIUM5.1The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec...
CVE-2026-66407HIGH8.1DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket privat...
CVE-2026-66406MEDIUM4.8DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle at...
CVE-2026-66405HIGH8.8DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to th...
CVE-2026-66404MEDIUM6.5DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activi...
CVE-2026-66403HIGH8.7DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log informatio...
CVE-2026-21084MEDIUM6.9Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information...
CVE-2026-21083MEDIUM6.8Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
CVE-2026-21082MEDIUM6.9Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
CVE-2026-21081MEDIUM5.1Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attacker...
CVE-2026-21080MEDIUM6.9Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access...
CVE-2026-21079HIGH7Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept tr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now