2026 CVE Vulnerabilities
66,522 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93208 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: kasan: fix cache shrink race with CPU hotplug kasa... |
| CVE-2026-93207 | CRITICAL | 9.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decod... |
| CVE-2026-93206 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: PCI/proc: Use file_ns_capable() when checking confi... |
| CVE-2026-93205 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Manage teardown with devm arm_s... |
| CVE-2026-92680 | MEDIUM | 5.5 | 0.2% | Sep 24, 2026 | Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the W... |
| CVE-2026-88371 | — | — | — | Sep 24, 2026 | ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing sp... |
| CVE-2026-88370 | MEDIUM | 5.3 | 0.1% | Sep 24, 2026 | libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and stri... |
| CVE-2026-88369 | HIGH | 7.3 | 0.2% | Sep 24, 2026 | zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump(). |
| CVE-2026-88368 | HIGH | 7.5 | — | Sep 24, 2026 | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() fu... |
| CVE-2026-88366 | — | — | — | Sep 24, 2026 | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG ar... |
| CVE-2026-88365 | CRITICAL | 9.8 | — | Sep 24, 2026 | minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-siz... |
| CVE-2026-88362 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted J... |
| CVE-2026-88361 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLab... |
| CVE-2026-88358 | MEDIUM | 6.5 | — | Sep 24, 2026 | simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafte... |
| CVE-2026-88357 | HIGH | 7.5 | — | Sep 24, 2026 | nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted ne... |
| CVE-2026-88355 | — | — | — | Sep 24, 2026 | An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expressi... |
| CVE-2026-79761 | MEDIUM | 6.6 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0... |
| CVE-2026-79760 | MEDIUM | 6.4 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0... |
| CVE-2026-79759 | MEDIUM | 4.3 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0... |
| CVE-2026-79758 | MEDIUM | 5.4 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0... |
| CVE-2026-77581 | HIGH | 8.6 | 0.3% | Sep 24, 2026 | BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS pr... |
| CVE-2026-76907 | MEDIUM | 6.5 | — | Sep 24, 2026 | LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/docum... |
| CVE-2026-75907 | HIGH | 7.5 | — | Sep 24, 2026 | The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID s... |
| CVE-2026-67233 | MEDIUM | 6 | — | Sep 24, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel ma... |
| CVE-2026-63630 | LOW | 3.4 | 0.3% | Sep 24, 2026 | BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Tim... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now