2026 CVE Vulnerabilities
66,554 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79759 | MEDIUM | 4.3 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0... |
| CVE-2026-79758 | MEDIUM | 5.4 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0... |
| CVE-2026-77581 | HIGH | 8.6 | 0.3% | Sep 24, 2026 | BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS pr... |
| CVE-2026-76907 | MEDIUM | 6.5 | — | Sep 24, 2026 | LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/docum... |
| CVE-2026-75907 | HIGH | 7.5 | — | Sep 24, 2026 | The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID s... |
| CVE-2026-67233 | MEDIUM | 6 | — | Sep 24, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel ma... |
| CVE-2026-63630 | LOW | 3.4 | 0.3% | Sep 24, 2026 | BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Tim... |
| CVE-2026-63203 | HIGH | 7.6 | — | Sep 24, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API han... |
| CVE-2026-56739 | HIGH | 8.5 | — | Sep 24, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-... |
| CVE-2026-56737 | HIGH | 8.1 | — | Sep 24, 2026 | phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its pub... |
| CVE-2026-97404 | CRITICAL | 9.2 | 0.3% | Sep 24, 2026 | In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty... |
| CVE-2026-97362 | HIGH | 7.5 | — | Sep 24, 2026 | HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause... |
| CVE-2026-97224 | MEDIUM | 4.3 | — | Sep 24, 2026 | A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file package... |
| CVE-2026-90959 | HIGH | 8.1 | 0.3% | Sep 24, 2026 | A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows ... |
| CVE-2026-90481 | CRITICAL | 9.2 | — | Sep 24, 2026 | In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occu... |
| CVE-2026-88351 | CRITICAL | 9.8 | 0.1% | Sep 24, 2026 | An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specia... |
| CVE-2026-82094 | HIGH | 7.1 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the s... |
| CVE-2026-82093 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to... |
| CVE-2026-81552 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-81549 | CRITICAL | 9.6 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ... |
| CVE-2026-81548 | HIGH | 8.8 | 0.8% | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-81547 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-81545 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-81539 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to... |
| CVE-2026-77874 | HIGH | 8.6 | — | Sep 24, 2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now