2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87453 | MEDIUM | 5.3 | 0.2% | Sep 9, 2026 | Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised... |
| CVE-2026-87449 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote att... |
| CVE-2026-87447 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social e... |
| CVE-2026-87446 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social eng... |
| CVE-2026-87445 | MEDIUM | 5.4 | 0.3% | Sep 9, 2026 | UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements v... |
| CVE-2026-87443 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive inf... |
| CVE-2026-87441 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system ac... |
| CVE-2026-87439 | MEDIUM | 5.3 | 0.3% | Sep 9, 2026 | Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised ... |
| CVE-2026-87437 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive informati... |
| CVE-2026-87436 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engine... |
| CVE-2026-87435 | MEDIUM | 5.3 | 0.3% | Sep 9, 2026 | Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromise... |
| CVE-2026-87432 | MEDIUM | 4.2 | 0.3% | Sep 9, 2026 | Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromi... |
| CVE-2026-87429 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had comprom... |
| CVE-2026-53937 | MEDIUM | 6.2 | 0.2% | Sep 9, 2026 | MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 th... |
| CVE-2026-53639 | MEDIUM | 6.3 | 0.5% | Sep 8, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, ... |
| CVE-2026-53638 | MEDIUM | 4.3 | 0.2% | Sep 8, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, ... |
| CVE-2026-53637 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 ... |
| CVE-2026-47680 | MEDIUM | 5.3 | — | Sep 8, 2026 | The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, ... |
| CVE-2026-18090 | MEDIUM | 6.1 | 0.2% | Sep 8, 2026 | A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by provid... |
| CVE-2026-86996 | MEDIUM | 5.4 | 0.2% | Sep 8, 2026 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow... |
| CVE-2026-86995 | MEDIUM | 4.3 | 0.3% | Sep 8, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the re... |
| CVE-2026-86994 | MEDIUM | 4.3 | 0.2% | Sep 8, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows en... |
| CVE-2026-86993 | MEDIUM | 4.9 | 0.3% | Sep 8, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destina... |
| CVE-2026-86085 | MEDIUM | 4.9 | 0.3% | Sep 8, 2026 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /r... |
| CVE-2026-86084 | MEDIUM | 5.5 | 0.3% | Sep 8, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and cal... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now