2026 CVE Vulnerabilities
44,115 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16396 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153,... |
| CVE-2026-16391 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140... |
| CVE-2026-16386 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi... |
| CVE-2026-16385 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi... |
| CVE-2026-16384 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi... |
| CVE-2026-16379 | HIGH | 8.8 | 0.4% | Jul 21, 2026 | Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 1... |
| CVE-2026-16378 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderb... |
| CVE-2026-16376 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16374 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR ... |
| CVE-2026-16373 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153. |
| CVE-2026-16372 | HIGH | 8.8 | 0.4% | Jul 21, 2026 | Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbir... |
| CVE-2026-16371 | HIGH | 8.8 | 0.4% | Jul 21, 2026 | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, ... |
| CVE-2026-16366 | HIGH | 8.8 | 0.4% | Jul 21, 2026 | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16365 | HIGH | 8.8 | 0.4% | Jul 21, 2026 | Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16362 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Th... |
| CVE-2026-16354 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115... |
| CVE-2026-60080 | HIGH | 7.3 | 0.2% | Jul 21, 2026 | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.... |
| CVE-2026-1771 | HIGH | 7.2 | 0.6% | Jul 21, 2026 | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFi... |
| CVE-2026-15370 | HIGH | 7.3 | 0.1% | Jul 21, 2026 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concaten... |
| CVE-2026-3183 | HIGH | 7.1 | — | Jul 21, 2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass. |
| CVE-2026-8082 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQ... |
| CVE-2026-11767 | HIGH | 8.8 | 0.2% | Jul 21, 2026 | The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values bef... |
| CVE-2026-59776 | HIGH | 7 | 0.1% | Jul 21, 2026 | Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v... |
| CVE-2026-6952 | HIGH | 7.2 | 0.9% | Jul 21, 2026 | A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B... |
| CVE-2026-16332 | HIGH | 7.3 | 0.5% | Jul 21, 2026 | A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_upload... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now