2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64918 | MEDIUM | 6.5 | 0.5% | Sep 8, 2026 | Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a netw... |
| CVE-2026-62801 | MEDIUM | 6.5 | 0.8% | Sep 8, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthori... |
| CVE-2026-62762 | MEDIUM | 6.5 | 1.1% | Sep 8, 2026 | Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ... |
| CVE-2026-58649 | MEDIUM | 6.5 | — | Sep 8, 2026 | Origin validation error in .NET allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-54611 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (R... |
| CVE-2026-86668 | MEDIUM | 4.3 | 0.3% | Sep 8, 2026 | A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function u... |
| CVE-2026-86667 | MEDIUM | 4.7 | — | Sep 8, 2026 | A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list o... |
| CVE-2026-84391 | MEDIUM | 6.5 | — | Sep 8, 2026 | A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial... |
| CVE-2026-84386 | MEDIUM | 5.1 | — | Sep 8, 2026 | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all vers... |
| CVE-2026-84385 | MEDIUM | 5.4 | 0.1% | Sep 8, 2026 | A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5... |
| CVE-2026-82076 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary data... |
| CVE-2026-82074 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user wit... |
| CVE-2026-82073 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges t... |
| CVE-2026-82070 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privile... |
| CVE-2026-82069 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privilege... |
| CVE-2026-82068 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal asse... |
| CVE-2026-82065 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection c... |
| CVE-2026-82063 | MEDIUM | 5.3 | 0.3% | Sep 8, 2026 | A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cau... |
| CVE-2026-82062 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled f... |
| CVE-2026-82060 | MEDIUM | 5.4 | 0.2% | Sep 8, 2026 | In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store d... |
| CVE-2026-82059 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user ... |
| CVE-2026-82058 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges ... |
| CVE-2026-82057 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod ... |
| CVE-2026-82056 | MEDIUM | 5.3 | 0.2% | Sep 8, 2026 | A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert ... |
| CVE-2026-82055 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer d... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now