2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86863 | CRITICAL | 9.8 | 0.4% | Sep 17, 2026 | pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse prox... |
| CVE-2026-88952 | CRITICAL | 9.1 | — | Sep 17, 2026 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another us... |
| CVE-2026-79752 | CRITICAL | 9.2 | — | Sep 17, 2026 | CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::ca... |
| CVE-2026-63472 | CRITICAL | 9.1 | — | Sep 17, 2026 | Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUse... |
| CVE-2026-92960 | CRITICAL | 10 | — | Sep 17, 2026 | vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandb... |
| CVE-2026-92957 | CRITICAL | 9.9 | 0.6% | Sep 17, 2026 | vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) ... |
| CVE-2026-92956 | CRITICAL | 10 | — | Sep 17, 2026 | vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on ... |
| CVE-2026-92955 | CRITICAL | 10 | — | Sep 17, 2026 | vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ g... |
| CVE-2026-92953 | CRITICAL | 10 | — | Sep 17, 2026 | vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation.... |
| CVE-2026-92951 | CRITICAL | 9.9 | — | Sep 17, 2026 | vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses no... |
| CVE-2026-92948 | CRITICAL | 9.9 | — | Sep 17, 2026 | vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on N... |
| CVE-2026-92947 | CRITICAL | 10 | — | Sep 17, 2026 | vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer... |
| CVE-2026-92946 | CRITICAL | 10 | — | Sep 17, 2026 | vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit re... |
| CVE-2026-92944 | CRITICAL | 9.8 | 0.6% | Sep 17, 2026 | vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally(... |
| CVE-2026-92941 | CRITICAL | 10 | — | Sep 17, 2026 | vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls... |
| CVE-2026-92940 | CRITICAL | 10 | — | Sep 17, 2026 | vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is e... |
| CVE-2026-92939 | CRITICAL | 9.9 | — | Sep 17, 2026 | vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed.... |
| CVE-2026-92938 | CRITICAL | 9.9 | 0.4% | Sep 17, 2026 | vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin ... |
| CVE-2026-92937 | CRITICAL | 10 | — | Sep 17, 2026 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for G... |
| CVE-2026-92935 | CRITICAL | 9 | — | Sep 17, 2026 | vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor compute... |
| CVE-2026-92934 | CRITICAL | 9 | — | Sep 17, 2026 | vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host... |
| CVE-2026-86533 | CRITICAL | 9.1 | — | Sep 17, 2026 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a r... |
| CVE-2026-85500 | CRITICAL | 9.1 | — | Sep 17, 2026 | Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to ... |
| CVE-2026-82761 | CRITICAL | 9.1 | — | Sep 17, 2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker hol... |
| CVE-2026-62108 | CRITICAL | 9.8 | — | Sep 17, 2026 | Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now