2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-86863CRITICAL9.8pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse prox...
CVE-2026-88952CRITICAL9.1Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another us...
CVE-2026-79752CRITICAL9.2CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::ca...
CVE-2026-63472CRITICAL9.1Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUse...
CVE-2026-92960CRITICAL10vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandb...
CVE-2026-92957CRITICAL9.9vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) ...
CVE-2026-92956CRITICAL10vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on ...
CVE-2026-92955CRITICAL10vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ g...
CVE-2026-92953CRITICAL10vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation....
CVE-2026-92951CRITICAL9.9vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses no...
CVE-2026-92948CRITICAL9.9vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on N...
CVE-2026-92947CRITICAL10vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer...
CVE-2026-92946CRITICAL10vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit re...
CVE-2026-92944CRITICAL9.8vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally(...
CVE-2026-92941CRITICAL10vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls...
CVE-2026-92940CRITICAL10vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is e...
CVE-2026-92939CRITICAL9.9vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed....
CVE-2026-92938CRITICAL9.9vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin ...
CVE-2026-92937CRITICAL10vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for G...
CVE-2026-92935CRITICAL9vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor compute...
CVE-2026-92934CRITICAL9vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host...
CVE-2026-86533CRITICAL9.1Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a r...
CVE-2026-85500CRITICAL9.1Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to ...
CVE-2026-82761CRITICAL9.1Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker hol...
CVE-2026-62108CRITICAL9.8Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now