2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13285 | HIGH | 7.1 | 0.4% | Sep 14, 2026 | IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could ... |
| CVE-2026-13275 | HIGH | 7.1 | 0.3% | Sep 14, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-13260 | HIGH | 7.5 | 0.4% | Sep 14, 2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of ... |
| CVE-2026-13107 | HIGH | 7.1 | 0.4% | Sep 14, 2026 | IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to X... |
| CVE-2026-82028 | HIGH | 8.8 | 0.4% | Sep 14, 2026 | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API serv... |
| CVE-2026-73496 | HIGH | 7.7 | 0.3% | Sep 14, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th... |
| CVE-2026-65838 | HIGH | 8.2 | 0.3% | Sep 14, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody f... |
| CVE-2026-54632 | HIGH | 7.5 | 0.5% | Sep 14, 2026 | SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the S... |
| CVE-2026-54629 | HIGH | 7.5 | — | Sep 14, 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtu... |
| CVE-2026-54628 | HIGH | 8.6 | 0.3% | Sep 14, 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtu... |
| CVE-2026-54447 | HIGH | 8.4 | — | Sep 14, 2026 | garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0.... |
| CVE-2026-47253 | HIGH | 7.3 | — | Sep 14, 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar functi... |
| CVE-2026-19816 | HIGH | 7.1 | 0.1% | Sep 14, 2026 | A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (... |
| CVE-2026-19624 | HIGH | 7.8 | 0.1% | Sep 14, 2026 | A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and v... |
| CVE-2026-17467 | HIGH | 8.2 | 0.3% | Sep 14, 2026 | IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due t... |
| CVE-2026-17416 | HIGH | 7.8 | 0.1% | Sep 14, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex... |
| CVE-2026-17156 | HIGH | 7.8 | 0.1% | Sep 14, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex... |
| CVE-2026-17133 | HIGH | 7.8 | 0.1% | Sep 14, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex... |
| CVE-2026-16673 | HIGH | 8.8 | 0.4% | Sep 14, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra... |
| CVE-2026-16466 | HIGH | 8.8 | 0.9% | Sep 14, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra... |
| CVE-2026-16432 | HIGH | 7.7 | 0.3% | Sep 14, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacke... |
| CVE-2026-16428 | HIGH | 8.8 | 0.5% | Sep 14, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra... |
| CVE-2026-16335 | HIGH | 8.1 | 0.4% | Sep 14, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or... |
| CVE-2026-15955 | HIGH | 7.5 | 0.4% | Sep 14, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file writ... |
| CVE-2026-90809 | HIGH | 7.3 | — | Sep 14, 2026 | A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_comman... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now