2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54160 | HIGH | 8.2 | — | Sep 28, 2026 | Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU... |
| CVE-2026-48100 | HIGH | 8.7 | — | Sep 28, 2026 | Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, a... |
| CVE-2026-101894 | CRITICAL | 9.1 | — | Sep 28, 2026 | The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) ... |
| CVE-2026-101891 | CRITICAL | 9.3 | — | Sep 28, 2026 | An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticate... |
| CVE-2026-101098 | MEDIUM | 4.3 | — | Sep 28, 2026 | A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the funct... |
| CVE-2026-101083 | MEDIUM | 5.3 | — | Sep 28, 2026 | A security vulnerability has been detected in PMWeb v7.x/v8.x/v2025.x. Impacted is an unknown function in the library en... |
| CVE-2026-101082 | MEDIUM | 5.3 | — | Sep 28, 2026 | A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown processing of the file downloade... |
| CVE-2026-101081 | CRITICAL | 9.1 | — | Sep 28, 2026 | A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp o... |
| CVE-2026-97399 | LOW | 3.7 | — | Sep 28, 2026 | The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte bey... |
| CVE-2026-93348 | HIGH | 8.1 | — | Sep 28, 2026 | Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code in... |
| CVE-2026-91154 | MEDIUM | 6.9 | — | Sep 28, 2026 | Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.... |
| CVE-2026-88808 | HIGH | 8.8 | — | Sep 28, 2026 | A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters ... |
| CVE-2026-88805 | HIGH | 8.1 | — | Sep 28, 2026 | Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the acco... |
| CVE-2026-88804 | CRITICAL | 9.6 | — | Sep 28, 2026 | An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripti... |
| CVE-2026-12342 | CRITICAL | 9.6 | — | Sep 28, 2026 | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the Id... |
| CVE-2026-101861 | MEDIUM | 4.1 | — | Sep 28, 2026 | Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows a... |
| CVE-2026-101080 | MEDIUM | 4.8 | — | Sep 28, 2026 | A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the ... |
| CVE-2026-101079 | LOW | 2.8 | — | Sep 28, 2026 | A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function i... |
| CVE-2026-101078 | MEDIUM | 6.3 | — | Sep 28, 2026 | A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the ... |
| CVE-2026-101077 | CRITICAL | 10 | — | Sep 28, 2026 | A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp ... |
| CVE-2026-101076 | CRITICAL | 10 | — | Sep 28, 2026 | A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_... |
| CVE-2026-96538 | HIGH | 8.7 | — | Sep 28, 2026 | WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in ... |
| CVE-2026-93540 | MEDIUM | 6.5 | — | Sep 28, 2026 | A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLa... |
| CVE-2026-93539 | MEDIUM | 5.4 | — | Sep 28, 2026 | A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is no... |
| CVE-2026-93538 | HIGH | 7.1 | — | Sep 28, 2026 | A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now