2026 CVE Vulnerabilities
61,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11317 | HIGH | 8.7 | 0.3% | Jun 16, 2026 | A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when ... |
| CVE-2026-10831 | MEDIUM | 6.9 | 0.3% | Jun 16, 2026 | A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The co... |
| CVE-2026-10640 | HIGH | 7.1 | 0.4% | Jun 16, 2026 | Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_... |
| CVE-2026-10639 | MEDIUM | 4.8 | 0.2% | Jun 16, 2026 | In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply... |
| CVE-2026-10638 | HIGH | 7.5 | 0.4% | Jun 16, 2026 | subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data... |
| CVE-2026-10637 | HIGH | 7.1 | 0.3% | Jun 16, 2026 | subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned s... |
| CVE-2026-10636 | LOW | 3.7 | 0.3% | Jun 16, 2026 | In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the pac... |
| CVE-2026-0647 | HIGH | 8.8 | 0.4% | Jun 16, 2026 | An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability ... |
| CVE-2026-0646 | HIGH | 8.7 | 0.3% | Jun 16, 2026 | A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol ... |
| CVE-2026-9507 | MEDIUM | 5.1 | 0.4% | Jun 16, 2026 | A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijac... |
| CVE-2026-53900 | MEDIUM | 4.3 | 0.1% | Jun 16, 2026 | Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument... |
| CVE-2026-53899 | MEDIUM | 6.5 | 0.1% | Jun 16, 2026 | Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suff... |
| CVE-2026-12330 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12,... |
| CVE-2026-12329 | MEDIUM | 5.3 | 0.3% | Jun 16, 2026 | Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 14... |
| CVE-2026-12328 | HIGH | 8.1 | 0.5% | Jun 16, 2026 | Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbir... |
| CVE-2026-12327 | HIGH | 8.1 | 0.4% | Jun 16, 2026 | Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these... |
| CVE-2026-12326 | HIGH | 8.1 | 0.3% | Jun 16, 2026 | Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption a... |
| CVE-2026-12325 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, ... |
| CVE-2026-12324 | HIGH | 7.3 | 0.2% | Jun 16, 2026 | Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firef... |
| CVE-2026-12323 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
| CVE-2026-12322 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
| CVE-2026-12321 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird... |
| CVE-2026-12320 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 15... |
| CVE-2026-12319 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 15... |
| CVE-2026-12318 | HIGH | 7.3 | 0.2% | Jun 16, 2026 | Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunder... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now