2026 CVE Vulnerabilities
59,282 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13375 | MEDIUM | 4.8 | 0.3% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2026-13374 | MEDIUM | 4.8 | 0.3% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2026-13373 | MEDIUM | 4.8 | 0.3% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2026-13371 | MEDIUM | 4.9 | 0.4% | Jul 3, 2026 | An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending ma... |
| CVE-2026-13368 | HIGH | 8.1 | 1.0% | Jul 3, 2026 | WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for th... |
| CVE-2026-13084 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create... |
| CVE-2026-13079 | HIGH | 7.8 | 0.1% | Jul 3, 2026 | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attac... |
| CVE-2026-13054 | HIGH | 7.2 | 0.6% | Jul 3, 2026 | A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacke... |
| CVE-2026-13053 | HIGH | 7.2 | 0.6% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe... |
| CVE-2026-13050 | HIGH | 7.2 | 0.7% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged ... |
| CVE-2026-57100 | HIGH | 8.8 | 0.6% | Jul 2, 2026 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to... |
| CVE-2026-54998 | HIGH | 8.8 | 0.6% | Jul 2, 2026 | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-45499 | HIGH | 8.8 | 0.6% | Jul 2, 2026 | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-41106 | CRITICAL | 9.3 | 0.5% | Jul 2, 2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege... |
| CVE-2026-26145 | CRITICAL | 9.8 | 0.3% | Jul 2, 2026 | Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-50722 | MEDIUM | 5.9 | 0.3% | Jul 2, 2026 | Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding o... |
| CVE-2026-50721 | MEDIUM | 5.9 | 0.4% | Jul 2, 2026 | Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authen... |
| CVE-2026-12413 | HIGH | 7.5 | 0.6% | Jul 2, 2026 | An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation wou... |
| CVE-2026-58460 | HIGH | 7.7 | 0.1% | Jul 2, 2026 | react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious applicat... |
| CVE-2026-52830 | CRITICAL | 9.4 | 0.4% | Jul 2, 2026 | fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t... |
| CVE-2026-52192 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead... |
| CVE-2026-52191 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-52189 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-52188 | MEDIUM | 6.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-38972 | HIGH | 7.8 | 0.1% | Jul 2, 2026 | Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Not... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now