2026 CVE Vulnerabilities

57,114 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13768CRITICAL10Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub R...
CVE-2026-13728MEDIUM4.4In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved...
CVE-2026-13722HIGH7.2WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore featu...
CVE-2026-13384HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged u...
CVE-2026-13383HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged ...
CVE-2026-13377MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13376MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13375MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13374MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13373MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13371MEDIUM4.9An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending ma...
CVE-2026-13368HIGH8.1WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for th...
CVE-2026-13084HIGH7.5A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create...
CVE-2026-13079HIGH7.8A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attac...
CVE-2026-13054HIGH7.2A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacke...
CVE-2026-13053HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2026-13050HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged ...
CVE-2026-57100HIGH8.8Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to...
CVE-2026-54998HIGH8.8Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-45499HIGH8.8Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
CVE-2026-41106CRITICAL9.3Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege...
CVE-2026-26145CRITICAL9.8Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
CVE-2026-50722MEDIUM5.9Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding o...
CVE-2026-50721MEDIUM5.9Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authen...
CVE-2026-12413HIGH7.5An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation wou...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now