2026 CVE Vulnerabilities

45,065 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-42222CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exist...
CVE-2026-42221CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticate...
CVE-2026-41926CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cg...
CVE-2026-41925CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi bin...
CVE-2026-41924CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest...
CVE-2026-41923CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cg...
CVE-2026-41922CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cg...
CVE-2026-42235CRITICAL9.6n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated a...
CVE-2026-42233CRITICAL9.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle...
CVE-2026-42796CRITICAL9.8Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoi...
CVE-2026-42087CRITICAL9.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-41571CRITICAL9.4Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls ba...
CVE-2026-42812CRITICAL9.9In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table ...
CVE-2026-42811CRITICAL9.9In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, bu...
CVE-2026-42810CRITICAL9.9Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access pol...
CVE-2026-42809CRITICAL9.9Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effectiv...
CVE-2026-42376CRITICAL9.8D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet...
CVE-2026-42090CRITICAL9.6Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and ...
CVE-2026-42076CRITICAL9.8Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability ...
CVE-2026-42027CRITICAL9.8Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5,...
CVE-2026-40682CRITICAL9.1XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affec...
CVE-2026-26956CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary...
CVE-2026-26332CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sa...
CVE-2026-25293CRITICAL9.8Buffer overflow due to incorrect authorization in PLC FW
CVE-2026-24781CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now