2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12666 | HIGH | 8.1 | 0.3% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12358 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of ... |
| CVE-2026-12355 | HIGH | 8.1 | 0.4% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12354 | HIGH | 7.5 | 0.5% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12150 | HIGH | 7 | 0.2% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12101 | HIGH | 8.1 | 0.1% | Sep 15, 2026 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to i... |
| CVE-2026-11934 | HIGH | 7.2 | 0.3% | Sep 15, 2026 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to i... |
| CVE-2026-11929 | HIGH | 7.5 | 0.2% | Sep 15, 2026 | IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptograph... |
| CVE-2026-11926 | HIGH | 7.5 | 0.3% | Sep 15, 2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of ... |
| CVE-2026-11729 | HIGH | 8.5 | 0.3% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-11728 | HIGH | 8.1 | 0.6% | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-91853 | HIGH | 7.4 | 1.4% | Sep 15, 2026 | A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvp... |
| CVE-2026-89022 | HIGH | 7.4 | 0.3% | Sep 15, 2026 | BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows ... |
| CVE-2026-81895 | HIGH | 7.2 | 0.3% | Sep 15, 2026 | In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] withou... |
| CVE-2026-63443 | HIGH | 8.3 | — | Sep 15, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10... |
| CVE-2026-59160 | HIGH | 8.8 | — | Sep 15, 2026 | Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts it... |
| CVE-2026-58201 | HIGH | 8.7 | — | Sep 15, 2026 | Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2... |
| CVE-2026-58200 | HIGH | 7.1 | — | Sep 15, 2026 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payloa... |
| CVE-2026-55692 | HIGH | 7.5 | — | Sep 15, 2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em... |
| CVE-2026-55691 | HIGH | 8.6 | 0.3% | Sep 15, 2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em... |
| CVE-2026-55690 | HIGH | 7.5 | — | Sep 15, 2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em... |
| CVE-2026-55149 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in ... |
| CVE-2026-21588 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9... |
| CVE-2026-21587 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data... |
| CVE-2026-21586 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now