2026 CVE Vulnerabilities
61,548 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42769 | MEDIUM | 5.3 | 0.3% | Jun 9, 2026 | Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Mana... |
| CVE-2026-42768 | LOW | 3.7 | 0.4% | Jun 9, 2026 | Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacke... |
| CVE-2026-42767 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer derefere... |
| CVE-2026-42766 | MEDIUM | 5.9 | 0.6% | Jun 9, 2026 | Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decr... |
| CVE-2026-42765 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the who... |
| CVE-2026-42764 | HIGH | 7.5 | 0.7% | Jun 9, 2026 | Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenS... |
| CVE-2026-42599 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes f... |
| CVE-2026-42573 | MEDIUM | 6.1 | 0.3% | Jun 9, 2026 | Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its ... |
| CVE-2026-42570 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ... |
| CVE-2026-42567 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the S... |
| CVE-2026-41108 | HIGH | 7 | 0.3% | Jun 9, 2026 | Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. |
| CVE-2026-41098 | HIGH | 8.4 | 0.8% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an autho... |
| CVE-2026-41092 | HIGH | 7.8 | 0.3% | Jun 9, 2026 | Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. |
| CVE-2026-40409 | HIGH | 7.8 | 0.3% | Jun 9, 2026 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-40404 | HIGH | 7.8 | 0.3% | Jun 9, 2026 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-40376 | HIGH | 8.1 | 0.7% | Jun 9, 2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-40371 | HIGH | 8.8 | 0.6% | Jun 9, 2026 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized... |
| CVE-2026-3088 | MEDIUM | 6.5 | 0.4% | Jun 9, 2026 | Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted reque... |
| CVE-2026-38615 | CRITICAL | 9.8 | 0.8% | Jun 9, 2026 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. |
| CVE-2026-35188 | MEDIUM | 5 | 0.2% | Jun 9, 2026 | Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ... |
| CVE-2026-34692 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting ... |
| CVE-2026-34335 | HIGH | 7 | 0.2% | Jun 9, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca... |
| CVE-2026-34183 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P... |
| CVE-2026-34182 | CRITICAL | 9.1 | 0.2% | Jun 9, 2026 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe... |
| CVE-2026-34181 | HIGH | 7.4 | 0.2% | Jun 9, 2026 | Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now