2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87551 | MEDIUM | 4.3 | 0.1% | Sep 9, 2026 | Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging soc... |
| CVE-2026-87550 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to pote... |
| CVE-2026-87549 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engi... |
| CVE-2026-87548 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass syste... |
| CVE-2026-87546 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote att... |
| CVE-2026-87545 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social... |
| CVE-2026-87543 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the ... |
| CVE-2026-87541 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the... |
| CVE-2026-87540 | MEDIUM | 5.4 | 0.2% | Sep 9, 2026 | Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elemen... |
| CVE-2026-87538 | MEDIUM | 4.2 | 0.2% | Sep 9, 2026 | Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer... |
| CVE-2026-87535 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker... |
| CVE-2026-87532 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass sy... |
| CVE-2026-87523 | MEDIUM | 5.3 | 0.2% | Sep 9, 2026 | Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engin... |
| CVE-2026-87522 | MEDIUM | 6.5 | 0.4% | Sep 9, 2026 | Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leverag... |
| CVE-2026-87519 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging soc... |
| CVE-2026-87518 | MEDIUM | 5.3 | 0.2% | Sep 9, 2026 | Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who h... |
| CVE-2026-87516 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-ori... |
| CVE-2026-87515 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social e... |
| CVE-2026-87513 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging so... |
| CVE-2026-87511 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-orig... |
| CVE-2026-87508 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin... |
| CVE-2026-87507 | MEDIUM | 5.4 | 0.2% | Sep 9, 2026 | UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social en... |
| CVE-2026-87503 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacke... |
| CVE-2026-87502 | MEDIUM | 4.2 | 0.2% | Sep 9, 2026 | Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the ... |
| CVE-2026-87501 | MEDIUM | 5.4 | 0.2% | Sep 9, 2026 | UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now