2026 CVE Vulnerabilities
64,734 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81657 | CRITICAL | 9.8 | 0.6% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system ... |
| CVE-2026-80442 | CRITICAL | 9.9 | 0.6% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCert... |
| CVE-2026-80441 | CRITICAL | 9.8 | 0.4% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the ge... |
| CVE-2026-75878 | CRITICAL | 9.1 | 0.5% | Sep 18, 2026 | IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated sessio... |
| CVE-2026-63647 | CRITICAL | 9.3 | 0.5% | Sep 18, 2026 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior t... |
| CVE-2026-61781 | CRITICAL | 9.9 | 0.6% | Sep 18, 2026 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_tim... |
| CVE-2026-58264 | CRITICAL | 9.8 | 0.8% | Sep 18, 2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth com... |
| CVE-2026-93762 | CRITICAL | 9.8 | 0.6% | Sep 18, 2026 | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes... |
| CVE-2026-92702 | CRITICAL | 9.1 | 0.3% | Sep 18, 2026 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ... |
| CVE-2026-92701 | CRITICAL | 9.1 | 0.3% | Sep 18, 2026 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ... |
| CVE-2026-61550 | CRITICAL | 9.8 | 0.7% | Sep 18, 2026 | Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC mes... |
| CVE-2026-59163 | CRITICAL | 9.1 | 0.3% | Sep 18, 2026 | Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_... |
| CVE-2026-93765 | CRITICAL | 9.1 | 0.5% | Sep 18, 2026 | Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. In... |
| CVE-2026-85497 | CRITICAL | 9.8 | 0.2% | Sep 18, 2026 | CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insu... |
| CVE-2026-81321 | CRITICAL | 9.8 | 0.2% | Sep 18, 2026 | CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker w... |
| CVE-2026-77240 | CRITICAL | 9.9 | 0.3% | Sep 18, 2026 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security... |
| CVE-2026-84383 | CRITICAL | 9.8 | — | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item... |
| CVE-2026-75031 | CRITICAL | 9.8 | — | Sep 18, 2026 | In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick qu... |
| CVE-2026-61682 | CRITICAL | 9.9 | 0.4% | Sep 18, 2026 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t... |
| CVE-2026-10858 | CRITICAL | 9.9 | — | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote... |
| CVE-2026-10747 | CRITICAL | 10 | 0.5% | Sep 18, 2026 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to... |
| CVE-2026-10027 | CRITICAL | 9.8 | 0.4% | Sep 18, 2026 | IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow whe... |
| CVE-2026-93606 | CRITICAL | 10 | — | Sep 18, 2026 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API... |
| CVE-2026-93605 | CRITICAL | 10 | 0.4% | Sep 18, 2026 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chi... |
| CVE-2026-93603 | CRITICAL | 10 | 0.4% | Sep 18, 2026 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now