2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54160HIGH8.2Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU...
CVE-2026-48100HIGH8.7Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, a...
CVE-2026-101894CRITICAL9.1The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) ...
CVE-2026-101891CRITICAL9.3An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticate...
CVE-2026-101098MEDIUM4.3A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the funct...
CVE-2026-101083MEDIUM5.3A security vulnerability has been detected in PMWeb v7.x/v8.x/v2025.x. Impacted is an unknown function in the library en...
CVE-2026-101082MEDIUM5.3A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown processing of the file downloade...
CVE-2026-101081CRITICAL9.1A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp o...
CVE-2026-97399LOW3.7The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte bey...
CVE-2026-93348HIGH8.1Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code in...
CVE-2026-91154MEDIUM6.9Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions....
CVE-2026-88808HIGH8.8A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters ...
CVE-2026-88805HIGH8.1Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the acco...
CVE-2026-88804CRITICAL9.6An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripti...
CVE-2026-12342CRITICAL9.6This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the Id...
CVE-2026-101861MEDIUM4.1Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows a...
CVE-2026-101080MEDIUM4.8A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the ...
CVE-2026-101079LOW2.8A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function i...
CVE-2026-101078MEDIUM6.3A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the ...
CVE-2026-101077CRITICAL10A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp ...
CVE-2026-101076CRITICAL10A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_...
CVE-2026-96538HIGH8.7WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in ...
CVE-2026-93540MEDIUM6.5A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLa...
CVE-2026-93539MEDIUM5.4A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is no...
CVE-2026-93538HIGH7.1A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now