2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6450MEDIUM5.3A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allow...
CVE-2026-6412MEDIUM4.3Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate proce...
CVE-2026-56445CRITICAL9.1The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.pa...
CVE-2026-38640HIGH7.5A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a De...
CVE-2026-38637HIGH7.5An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of S...
CVE-2026-37452HIGH7.5Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit...
CVE-2026-12473HIGH8.3Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter wit...
CVE-2026-7531CRITICAL9.8Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1...
CVE-2026-57522MEDIUM5Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens()...
CVE-2026-57521MEDIUM5.3Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to ac...
CVE-2026-57520HIGH7.1Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users wi...
CVE-2026-55964MEDIUM5.3Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to ha...
CVE-2026-55960HIGH7.5Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw pub...
CVE-2026-55958HIGH7.5Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding th...
CVE-2026-46602HIGH7.5The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image cont...
CVE-2026-46601HIGH7.5The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.
CVE-2026-37454HIGH7.5Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit...
CVE-2026-37453HIGH7.5Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit...
CVE-2026-37149HIGH7.7GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerabil...
CVE-2026-2299MEDIUM4.3The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoi...
CVE-2026-12340HIGH7.5Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 si...
CVE-2026-11310HIGH7.5X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects on...
CVE-2026-10592MEDIUM5.3Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildca...
CVE-2026-10512HIGH7.5The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so...
CVE-2026-10097HIGH7.5wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now