2026 CVE Vulnerabilities

43,188 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-9205CRITICAL9.8IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
CVE-2026-8470CRITICAL9.1IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's...
CVE-2026-48168CRITICAL10PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vuln...
CVE-2026-70426CRITICAL9In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2...
CVE-2026-20310CRITICAL9.1As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t...
CVE-2026-20304CRITICAL9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t...
CVE-2026-20303CRITICAL9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t...
CVE-2026-20272CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t...
CVE-2026-20267CRITICAL9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t...
CVE-2026-17617CRITICAL9.8IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insuffici...
CVE-2026-9195CRITICAL9.3A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a...
CVE-2026-9193CRITICAL9.9An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and ...
CVE-2026-9192CRITICAL9.8An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allo...
CVE-2026-9190CRITICAL9.1An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 all...
CVE-2026-8709CRITICAL9.9An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server bef...
CVE-2026-8400CRITICAL9.8IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a f...
CVE-2026-7557CRITICAL9.1An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogi...
CVE-2026-7329CRITICAL9.9An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic...
CVE-2026-60053CRITICAL9.1Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin...
CVE-2026-39923CRITICAL9.2Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers t...
CVE-2026-16442CRITICAL9.8A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authenti...
CVE-2026-15587CRITICAL9.4Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows...
CVE-2026-10025CRITICAL9.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injec...
CVE-2026-16443CRITICAL9.1A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine ...
CVE-2026-71289CRITICAL9.8The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now