2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58502 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow r... |
| CVE-2026-58485 | HIGH | 7.1 | — | Sep 15, 2026 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through ... |
| CVE-2026-58483 | HIGH | 7.5 | — | Sep 15, 2026 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through ... |
| CVE-2026-57441 | HIGH | 8.4 | — | Sep 15, 2026 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, ... |
| CVE-2026-56829 | HIGH | 8.1 | — | Sep 15, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantSto... |
| CVE-2026-56827 | HIGH | 8.1 | — | Sep 15, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/At... |
| CVE-2026-56825 | HIGH | 8.1 | 0.5% | Sep 15, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/Collecti... |
| CVE-2026-55225 | HIGH | 8 | — | Sep 15, 2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I... |
| CVE-2026-54549 | HIGH | 8.3 | 0.2% | Sep 15, 2026 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, th... |
| CVE-2026-54547 | HIGH | 7.4 | 0.4% | Sep 15, 2026 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, Au... |
| CVE-2026-54251 | HIGH | 8.7 | — | Sep 15, 2026 | netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0... |
| CVE-2026-52484 | HIGH | 8.8 | 0.5% | Sep 15, 2026 | An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code... |
| CVE-2026-44300 | HIGH | 8.8 | — | Sep 15, 2026 | OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpo... |
| CVE-2026-40058 | HIGH | 8.8 | 0.1% | Sep 15, 2026 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability on... |
| CVE-2026-18115 | HIGH | 7.4 | 0.2% | Sep 15, 2026 | Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoi... |
| CVE-2026-18113 | HIGH | 7.5 | 0.3% | Sep 15, 2026 | In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing ... |
| CVE-2026-13210 | HIGH | 7.7 | 0.4% | Sep 15, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 1... |
| CVE-2026-12752 | HIGH | 7.1 | 0.5% | Sep 15, 2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) atta... |
| CVE-2026-12728 | HIGH | 8.8 | 0.6% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12667 | HIGH | 7.1 | 0.4% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12666 | HIGH | 8.1 | 0.3% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12358 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of ... |
| CVE-2026-12355 | HIGH | 8.1 | 0.4% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12354 | HIGH | 7.5 | 0.5% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12150 | HIGH | 7 | 0.2% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now