2026 CVE Vulnerabilities

59,800 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44628HIGH8.7An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called...
CVE-2026-13207HIGH8.7FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the R...
CVE-2026-11594MEDIUM6.1IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ...
CVE-2026-10562MEDIUM5.9An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of use...
CVE-2026-9836HIGH7.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
CVE-2026-9002MEDIUM6.5IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to...
CVE-2026-7874CRITICAL9.1IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak...
CVE-2026-7873CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive...
CVE-2026-7871CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application pri...
CVE-2026-7803CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with...
CVE-2026-7663CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and...
CVE-2026-3602MEDIUM5.5IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 1...
CVE-2026-13773CRITICAL10IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme S...
CVE-2026-13772CRITICAL9.9IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class nam...
CVE-2026-13759HIGH8.8IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, Objec...
CVE-2026-13449CRITICAL9.1IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE...
CVE-2026-12086MEDIUM5.5IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug...
CVE-2026-12085MEDIUM6.5IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8....
CVE-2026-12084HIGH7.5IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which...
CVE-2026-11906MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2026-11806HIGH7.5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability...
CVE-2026-11714CRITICAL9.8IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscover...
CVE-2026-11712CRITICAL9.3IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ...
CVE-2026-11708CRITICAL9.3IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ...
CVE-2026-11595HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the adm...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now