2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93606 | CRITICAL | 10 | — | Sep 18, 2026 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API... |
| CVE-2026-93605 | CRITICAL | 10 | 0.4% | Sep 18, 2026 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chi... |
| CVE-2026-93603 | CRITICAL | 10 | 0.4% | Sep 18, 2026 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge... |
| CVE-2026-93019 | CRITICAL | 9.1 | — | Sep 18, 2026 | Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_pa... |
| CVE-2026-13684 | CRITICAL | 9.8 | — | Sep 18, 2026 | An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-6905... |
| CVE-2026-13639 | CRITICAL | 9.8 | — | Sep 18, 2026 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-... |
| CVE-2026-67101 | CRITICAL | 9.3 | 0.3% | Sep 18, 2026 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functional... |
| CVE-2026-67100 | CRITICAL | 9.8 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. w... |
| CVE-2026-84738 | CRITICAL | 9.1 | — | Sep 18, 2026 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import f... |
| CVE-2026-93467 | CRITICAL | 9.8 | — | Sep 18, 2026 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execu... |
| CVE-2026-85878 | CRITICAL | 9.9 | 0.8% | Sep 18, 2026 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a netwo... |
| CVE-2026-69843 | CRITICAL | 10 | 0.9% | Sep 18, 2026 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwo... |
| CVE-2026-62874 | CRITICAL | 10 | 0.3% | Sep 18, 2026 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges ov... |
| CVE-2026-87701 | CRITICAL | 9.6 | 0.4% | Sep 17, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB al... |
| CVE-2026-85889 | CRITICAL | 9.8 | 0.9% | Sep 17, 2026 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges o... |
| CVE-2026-83944 | CRITICAL | 9.1 | 0.8% | Sep 17, 2026 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-70200 | CRITICAL | 9.8 | 0.9% | Sep 17, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize... |
| CVE-2026-70009 | CRITICAL | 9.8 | 0.7% | Sep 17, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attac... |
| CVE-2026-69865 | CRITICAL | 10 | 0.8% | Sep 17, 2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elev... |
| CVE-2026-69399 | CRITICAL | 9.8 | 0.9% | Sep 17, 2026 | Azure Arc Elevation of Privilege Vulnerability |
| CVE-2026-76949 | CRITICAL | 9.1 | — | Sep 17, 2026 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a re... |
| CVE-2026-73639 | CRITICAL | 9.1 | 0.2% | Sep 17, 2026 | Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tR... |
| CVE-2026-54767 | CRITICAL | 9.1 | — | Sep 17, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php... |
| CVE-2026-54734 | CRITICAL | 10 | 0.4% | Sep 17, 2026 | Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-suppl... |
| CVE-2026-54670 | CRITICAL | 9.1 | 0.6% | Sep 17, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/cont... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now