2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87107 | MEDIUM | 5.4 | — | Sep 10, 2026 | Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow... |
| CVE-2026-87106 | MEDIUM | 6.5 | — | Sep 10, 2026 | Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenti... |
| CVE-2026-68527 | MEDIUM | 5.9 | — | Sep 10, 2026 | Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (c... |
| CVE-2026-89045 | MEDIUM | 4 | 0.1% | Sep 10, 2026 | zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.rea... |
| CVE-2026-89044 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the f... |
| CVE-2026-88055 | MEDIUM | 5.5 | — | Sep 10, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-88054 | MEDIUM | 5.5 | 0.2% | Sep 10, 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rej... |
| CVE-2026-88028 | MEDIUM | 6.5 | — | Sep 10, 2026 | Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB inte... |
| CVE-2026-88026 | MEDIUM | 6.5 | — | Sep 10, 2026 | Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# D... |
| CVE-2026-15417 | MEDIUM | 6.9 | — | Sep 10, 2026 | In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to ... |
| CVE-2026-88050 | MEDIUM | 5.5 | 0.2% | Sep 10, 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharco... |
| CVE-2026-88049 | MEDIUM | 5.5 | 0.2% | Sep 10, 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks t... |
| CVE-2026-88046 | MEDIUM | 5.3 | 0.3% | Sep 10, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-52097 | MEDIUM | 6.8 | — | Sep 10, 2026 | An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (u... |
| CVE-2026-88940 | MEDIUM | 5.3 | — | Sep 10, 2026 | knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attac... |
| CVE-2026-88938 | MEDIUM | 6.5 | 0.3% | Sep 10, 2026 | knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agen... |
| CVE-2026-88015 | MEDIUM | 5.3 | 0.4% | Sep 10, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-88014 | MEDIUM | 6.3 | 0.1% | Sep 10, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.... |
| CVE-2026-88013 | MEDIUM | 5.3 | 0.2% | Sep 10, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.... |
| CVE-2026-88012 | MEDIUM | 5.3 | 0.3% | Sep 10, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints ... |
| CVE-2026-87913 | MEDIUM | 5.9 | — | Sep 10, 2026 | A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote ... |
| CVE-2026-87912 | MEDIUM | 5.9 | — | Sep 10, 2026 | A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.... |
| CVE-2026-81052 | MEDIUM | 6.8 | 0.1% | Sep 10, 2026 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An una... |
| CVE-2026-81051 | MEDIUM | 6.6 | 0.2% | Sep 10, 2026 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerabilit... |
| CVE-2026-81049 | MEDIUM | 6.7 | 0.1% | Sep 10, 2026 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high priv... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now