2026 CVE Vulnerabilities

45,001 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-34659CRITICAL9.6Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerabili...
CVE-2026-44343CRITICAL9.8WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard t...
CVE-2026-44277CRITICAL9.8A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticat...
CVE-2026-44196CRITICAL9.1Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication...
CVE-2026-44183CRITICAL9.8Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c...
CVE-2026-42898CRITICAL9.9Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a...
CVE-2026-42833CRITICAL9.1Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a...
CVE-2026-42823CRITICAL9.9Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-42300CRITICAL9.3DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware acc...
CVE-2026-42048CRITICAL9.6Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to...
CVE-2026-41103CRITICAL9.1Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unautho...
CVE-2026-41096CRITICAL9.8Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-41089CRITICAL9.8Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
CVE-2026-40402CRITICAL9.3Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
CVE-2026-33821CRITICAL9.9Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privi...
CVE-2026-33117CRITICAL9.1The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path...
CVE-2026-31242CRITICAL9.1The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via...
CVE-2026-31239CRITICAL9.8The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-train...
CVE-2026-31238CRITICAL9.8The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. Whe...
CVE-2026-31237CRITICAL9.8The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When ...
CVE-2026-31236CRITICAL9.8The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument....
CVE-2026-31235CRITICAL9.8The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within...
CVE-2026-31234CRITICAL9.8Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. T...
CVE-2026-31233CRITICAL9.8Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. Whe...
CVE-2026-31231CRITICAL9.8Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now