2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90840 | HIGH | 7.3 | 0.4% | Sep 15, 2026 | A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of ... |
| CVE-2026-91200 | HIGH | 8.8 | 0.4% | Sep 14, 2026 | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attack... |
| CVE-2026-91145 | HIGH | 7.1 | 0.4% | Sep 14, 2026 | Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to ... |
| CVE-2026-91144 | HIGH | 7.5 | 0.5% | Sep 14, 2026 | ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoi... |
| CVE-2026-91143 | HIGH | 7.2 | 0.3% | Sep 14, 2026 | goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated... |
| CVE-2026-18117 | HIGH | 7.3 | 0.3% | Sep 14, 2026 | Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because th... |
| CVE-2026-12756 | HIGH | 7.1 | 0.5% | Sep 14, 2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) atta... |
| CVE-2026-90896 | HIGH | 8.2 | 0.4% | Sep 14, 2026 | Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checko... |
| CVE-2026-90819 | HIGH | 7.3 | 0.4% | Sep 14, 2026 | A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSe... |
| CVE-2026-86917 | HIGH | 7.8 | 0.1% | Sep 14, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequo... |
| CVE-2026-86904 | HIGH | 7.5 | 0.1% | Sep 14, 2026 | A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 an... |
| CVE-2026-86901 | HIGH | 7.1 | 0.1% | Sep 14, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. M... |
| CVE-2026-86895 | HIGH | 7.5 | 0.2% | Sep 14, 2026 | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 2... |
| CVE-2026-86894 | HIGH | 7.5 | 0.2% | Sep 14, 2026 | A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to bre... |
| CVE-2026-84632 | HIGH | 7.3 | 0.1% | Sep 14, 2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadO... |
| CVE-2026-84631 | HIGH | 7.8 | 0.1% | Sep 14, 2026 | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be ... |
| CVE-2026-84629 | HIGH | 7.5 | 0.2% | Sep 14, 2026 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visio... |
| CVE-2026-84623 | HIGH | 7.5 | 0.2% | Sep 14, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iO... |
| CVE-2026-84620 | HIGH | 7.3 | 0.2% | Sep 14, 2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2... |
| CVE-2026-84611 | HIGH | 7.3 | 0.1% | Sep 14, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.... |
| CVE-2026-84607 | HIGH | 7.8 | 0.2% | Sep 14, 2026 | A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 a... |
| CVE-2026-84606 | HIGH | 7.5 | 0.3% | Sep 14, 2026 | A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS ... |
| CVE-2026-84598 | HIGH | 7.5 | 0.2% | Sep 14, 2026 | A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS... |
| CVE-2026-84584 | HIGH | 8.4 | 0.1% | Sep 14, 2026 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be ... |
| CVE-2026-84581 | HIGH | 8.4 | 0.2% | Sep 14, 2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now