2026 CVE Vulnerabilities
64,922 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79588 | MEDIUM | 4.3 | 0.1% | Sep 8, 2026 | U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP. |
| CVE-2026-78971 | MEDIUM | 4.6 | 0.2% | Sep 8, 2026 | In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attac... |
| CVE-2026-78742 | MEDIUM | 6.1 | 0.1% | Sep 8, 2026 | Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction. |
| CVE-2026-78741 | MEDIUM | 6.1 | 0.1% | Sep 8, 2026 | Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature. |
| CVE-2026-78738 | MEDIUM | 6.1 | 0.1% | Sep 8, 2026 | Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature. |
| CVE-2026-78635 | MEDIUM | 5 | 0.2% | Sep 8, 2026 | The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to ... |
| CVE-2026-78631 | MEDIUM | 5.5 | 0.1% | Sep 8, 2026 | The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log le... |
| CVE-2026-78630 | MEDIUM | 6.7 | 0.2% | Sep 8, 2026 | The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script... |
| CVE-2026-78629 | MEDIUM | 5.5 | 0.1% | Sep 8, 2026 | The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's poli... |
| CVE-2026-78622 | MEDIUM | 6 | 0.1% | Sep 8, 2026 | The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before ... |
| CVE-2026-19625 | MEDIUM | 5.3 | 0.3% | Sep 8, 2026 | When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1"... |
| CVE-2026-85630 | MEDIUM | 6.1 | 0.2% | Sep 8, 2026 | HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process... |
| CVE-2026-85485 | MEDIUM | 6.1 | 0.2% | Sep 8, 2026 | HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table fo... |
| CVE-2026-85484 | MEDIUM | 6.1 | 0.2% | Sep 8, 2026 | HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without... |
| CVE-2026-79905 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2026-78627 | MEDIUM | 5.5 | 0.1% | Sep 8, 2026 | The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The cred... |
| CVE-2026-78626 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rul... |
| CVE-2026-78625 | MEDIUM | 6.7 | 0.2% | Sep 8, 2026 | The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration fi... |
| CVE-2026-78624 | MEDIUM | 4.9 | 0.4% | Sep 8, 2026 | The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. ... |
| CVE-2026-78620 | MEDIUM | 4.9 | 0.3% | Sep 8, 2026 | The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before w... |
| CVE-2026-78579 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search fil... |
| CVE-2026-78574 | MEDIUM | 6.3 | 0.1% | Sep 8, 2026 | The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive... |
| CVE-2026-78560 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client... |
| CVE-2026-78552 | MEDIUM | 4.9 | 0.3% | Sep 8, 2026 | The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field... |
| CVE-2026-78550 | MEDIUM | 6.6 | 0.4% | Sep 8, 2026 | The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authentic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now