2026 CVE Vulnerabilities

61,338 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46612HIGH8.8Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-45062HIGH8.1FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function...
CVE-2026-20260MEDIUM4.3In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker coul...
CVE-2026-20259MEDIUM5.5In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.1...
CVE-2026-20258MEDIUM5.4In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-20257MEDIUM5.7In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-20256MEDIUM5.7In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-20255MEDIUM5.7In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-20254MEDIUM5.7In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-20253CRITICAL9.8In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or tr...
CVE-2026-20252HIGH7.6In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-20251HIGH8.8In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.1...
CVE-2026-11596MEDIUM4.7In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an au...
CVE-2026-11417HIGH7.3OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) mi...
CVE-2026-46616MEDIUM6.1Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to s...
CVE-2026-46609MEDIUM4.6Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML int...
CVE-2026-53698MEDIUM6.5Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.
CVE-2026-53694HIGH7.3Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Arg...
CVE-2026-53693MEDIUM6.9A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering pa...
CVE-2026-49760MEDIUM5.5Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulner...
CVE-2026-49759HIGH8.2Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to cra...
CVE-2026-48860MEDIUM6.5Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated ...
CVE-2026-48859MEDIUM5.3Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated rem...
CVE-2026-48858MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and S...
CVE-2026-48856MEDIUM6.5Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Dat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now