2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16141 | HIGH | 8.1 | 0.4% | Sep 15, 2026 | OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force th... |
| CVE-2026-16140 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an e... |
| CVE-2026-92076 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.... |
| CVE-2026-92074 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunde... |
| CVE-2026-92073 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.... |
| CVE-2026-92072 | HIGH | 8 | 0.1% | Sep 15, 2026 | Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 1... |
| CVE-2026-92067 | HIGH | 8.8 | 0.1% | Sep 15, 2026 | Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird... |
| CVE-2026-92065 | HIGH | 8.8 | 0.1% | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire... |
| CVE-2026-92064 | HIGH | 8.8 | 0.1% | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire... |
| CVE-2026-92062 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, T... |
| CVE-2026-92060 | HIGH | 8.8 | 0.1% | Sep 15, 2026 | Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Th... |
| CVE-2026-92058 | HIGH | 8.8 | 0.1% | Sep 15, 2026 | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 15... |
| CVE-2026-92056 | HIGH | 8.8 | 0.1% | Sep 15, 2026 | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderb... |
| CVE-2026-92055 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderb... |
| CVE-2026-92054 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbir... |
| CVE-2026-92053 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 15... |
| CVE-2026-92052 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in... |
| CVE-2026-92049 | HIGH | 8.8 | 0.1% | Sep 15, 2026 | Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbi... |
| CVE-2026-92047 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, T... |
| CVE-2026-92046 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 15... |
| CVE-2026-92044 | HIGH | 7.5 | 0.2% | Sep 15, 2026 | Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3... |
| CVE-2026-92043 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in ... |
| CVE-2026-92042 | HIGH | 7.5 | 0.2% | Sep 15, 2026 | Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ... |
| CVE-2026-92040 | HIGH | 8.8 | 0.1% | Sep 15, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156... |
| CVE-2026-92033 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now