2026 CVE Vulnerabilities

59,282 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13375MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13374MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13373MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13371MEDIUM4.9An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending ma...
CVE-2026-13368HIGH8.1WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for th...
CVE-2026-13084HIGH7.5A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create...
CVE-2026-13079HIGH7.8A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attac...
CVE-2026-13054HIGH7.2A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacke...
CVE-2026-13053HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2026-13050HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged ...
CVE-2026-57100HIGH8.8Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to...
CVE-2026-54998HIGH8.8Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-45499HIGH8.8Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
CVE-2026-41106CRITICAL9.3Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege...
CVE-2026-26145CRITICAL9.8Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
CVE-2026-50722MEDIUM5.9Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding o...
CVE-2026-50721MEDIUM5.9Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authen...
CVE-2026-12413HIGH7.5An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation wou...
CVE-2026-58460HIGH7.7react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious applicat...
CVE-2026-52830CRITICAL9.4fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t...
CVE-2026-52192HIGH7.5An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead...
CVE-2026-52191HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52189HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52188MEDIUM6.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-38972HIGH7.8Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Not...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now