2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76959 | MEDIUM | 4.6 | 0.1% | Sep 8, 2026 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on c... |
| CVE-2026-44766 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious in... |
| CVE-2026-82758 | MEDIUM | 6.3 | 0.4% | Sep 7, 2026 | Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker... |
| CVE-2026-82757 | MEDIUM | 6.3 | 0.4% | Sep 7, 2026 | Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who ... |
| CVE-2026-82756 | MEDIUM | 6.3 | 0.4% | Sep 7, 2026 | Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthen... |
| CVE-2026-82755 | MEDIUM | 6.3 | 0.4% | Sep 7, 2026 | Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a sha... |
| CVE-2026-82754 | MEDIUM | 6.3 | 0.4% | Sep 7, 2026 | Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-ch... |
| CVE-2026-86436 | MEDIUM | 5.4 | 0.3% | Sep 7, 2026 | Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing aut... |
| CVE-2026-86506 | MEDIUM | 5.9 | 0.2% | Sep 7, 2026 | In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed prof... |
| CVE-2026-86500 | MEDIUM | 5.5 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant th... |
| CVE-2026-86499 | MEDIUM | 4.3 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of vis... |
| CVE-2026-86497 | MEDIUM | 6.8 | 0.3% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administra... |
| CVE-2026-86496 | MEDIUM | 4.3 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email... |
| CVE-2026-86495 | MEDIUM | 6.5 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccess... |
| CVE-2026-86493 | MEDIUM | 6.5 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteb... |
| CVE-2026-86490 | MEDIUM | 6.5 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app imp... |
| CVE-2026-86489 | MEDIUM | 6.5 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders a... |
| CVE-2026-86488 | MEDIUM | 6.5 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved se... |
| CVE-2026-86484 | MEDIUM | 4.6 | 0.4% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS |
| CVE-2026-86483 | MEDIUM | 5.4 | 0.4% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible |
| CVE-2026-86481 | MEDIUM | 4.3 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons |
| CVE-2026-80176 | MEDIUM | 4.7 | 0.1% | Sep 7, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-80167 | MEDIUM | 5.5 | 0.1% | Sep 7, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-80126 | MEDIUM | 6.5 | 0.2% | Sep 7, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-80125 | MEDIUM | 5.9 | 0.2% | Sep 7, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now