2026 CVE Vulnerabilities

64,734 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-81657CRITICAL9.8IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system ...
CVE-2026-80442CRITICAL9.9IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCert...
CVE-2026-80441CRITICAL9.8IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the ge...
CVE-2026-75878CRITICAL9.1IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated sessio...
CVE-2026-63647CRITICAL9.3CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior t...
CVE-2026-61781CRITICAL9.9pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_tim...
CVE-2026-58264CRITICAL9.8FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth com...
CVE-2026-93762CRITICAL9.8Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes...
CVE-2026-92702CRITICAL9.1Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ...
CVE-2026-92701CRITICAL9.1Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ...
CVE-2026-61550CRITICAL9.8Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC mes...
CVE-2026-59163CRITICAL9.1Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_...
CVE-2026-93765CRITICAL9.1Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. In...
CVE-2026-85497CRITICAL9.8CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insu...
CVE-2026-81321CRITICAL9.8CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker w...
CVE-2026-77240CRITICAL9.9WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security...
CVE-2026-84383CRITICAL9.8libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item...
CVE-2026-75031CRITICAL9.8In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick qu...
CVE-2026-61682CRITICAL9.9kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t...
CVE-2026-10858CRITICAL9.9IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote...
CVE-2026-10747CRITICAL10IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to...
CVE-2026-10027CRITICAL9.8IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow whe...
CVE-2026-93606CRITICAL10vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API...
CVE-2026-93605CRITICAL10vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chi...
CVE-2026-93603CRITICAL10vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now