2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46734HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulner...
CVE-2026-46733HIGH7.8Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerabil...
CVE-2026-46732HIGH7Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resou...
CVE-2026-42390MEDIUM5.3An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured wit...
CVE-2026-42389MEDIUM5.3This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative ...
CVE-2026-42388MEDIUM5.9Incomplete validation of the SOA record present in a catalog zone might lead to a crash.
CVE-2026-42387MEDIUM5.9A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recur...
CVE-2026-41120CRITICAL9.8Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust...
CVE-2026-40012MEDIUM5.3ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have...
CVE-2026-2815HIGH8.4Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys
CVE-2026-27366HIGH7.5Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
CVE-2026-12755LOW2.7Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows ...
CVE-2026-42004LOW3.7An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten ...
CVE-2026-40211MEDIUM5.3An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed...
CVE-2026-40210MEDIUM4.8An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being se...
CVE-2026-40209MEDIUM5.3An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of bei...
CVE-2026-40208LOW3.7An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame...
CVE-2026-40011LOW3.7An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a...
CVE-2026-33612HIGH7.5A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
CVE-2026-42005MEDIUM4.3An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a den...
CVE-2026-56130LOW2"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie ...
CVE-2026-56091HIGH8.2When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause...
CVE-2026-54226MEDIUM6.4A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended...
CVE-2026-53277HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock for page table walks...
CVE-2026-53276HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix a use-after-free of the hci_con...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now