2026 CVE Vulnerabilities

61,700 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10586HIGH7.2The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Serv...
CVE-2026-48579HIGH7.5Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a netwo...
CVE-2026-48567CRITICAL9.8Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a networ...
CVE-2026-47655MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose ...
CVE-2026-47644HIGH7.5Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Micr...
CVE-2026-45497HIGH8.8Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an autho...
CVE-2026-42824HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-20245HIGH7.8A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, f...
CVE-2026-11237HIGH8.3Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh...
CVE-2026-11236HIGH8.3Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who h...
CVE-2026-11235HIGH8.8Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had...
CVE-2026-11234MEDIUM4.3Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had c...
CVE-2026-11233MEDIUM4.7Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who ha...
CVE-2026-11232MEDIUM5.4Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform U...
CVE-2026-11231HIGH8.1Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker t...
CVE-2026-11230HIGH8.8Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code...
CVE-2026-11229MEDIUM6.1Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform p...
CVE-2026-11228MEDIUM4.3Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinc...
CVE-2026-11227MEDIUM6.5Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform do...
CVE-2026-11226MEDIUM6.5Insufficient policy enforcement in PreviewTab in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attack...
CVE-2026-11225MEDIUM6.5Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domai...
CVE-2026-11224HIGH8.1Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbit...
CVE-2026-11223MEDIUM6.5Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker ...
CVE-2026-11222MEDIUM6.5Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain s...
CVE-2026-11221MEDIUM4.3Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now