2026 CVE Vulnerabilities

45,056 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-44112CRITICAL9.6OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes tha...
CVE-2026-44109CRITICAL9.8OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation t...
CVE-2026-43585CRITICAL9.8OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali...
CVE-2026-43581CRITICAL9.6OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that expos...
CVE-2026-43578CRITICAL9.1OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrad...
CVE-2026-43575CRITICAL9.8OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper ...
CVE-2026-7910CRITICAL9.6Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the render...
CVE-2026-7908CRITICAL9.6Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a ...
CVE-2026-41930CRITICAL9.8Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configura...
CVE-2026-0300CRITICAL9.8A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks...
CVE-2026-7875CRITICAL9.3NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment hand...
CVE-2026-5081CRITICAL9.1Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Sessi...
CVE-2026-43208CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: do not pass flow_id to set_rps_cpu() Blamed c...
CVE-2026-43198CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() ...
CVE-2026-43197CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-termina...
CVE-2026-43186CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fil...
CVE-2026-43185CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_n...
CVE-2026-43125CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The le...
CVE-2026-43117CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from den...
CVE-2026-43114CRITICAL9.4In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-ma...
CVE-2026-43083CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->t...
CVE-2026-40010CRITICAL9.1Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a sessi...
CVE-2026-28780CRITICAL9.8Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a maliciou...
CVE-2026-35579CRITICAL9.8CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementati...
CVE-2026-40331CRITICAL9.3Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now