2026 CVE Vulnerabilities

61,771 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50208CRITICAL9.4High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc...
CVE-2026-50207HIGH7.8The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read base...
CVE-2026-3820HIGH7.2There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain admini...
CVE-2026-50206MEDIUM6.8Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou...
CVE-2026-50205HIGH8.2System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identifi...
CVE-2026-49204MEDIUM6.5Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
CVE-2026-49203HIGH8.3Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote prof...
CVE-2026-49202HIGH8.6Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S...
CVE-2026-49194HIGH8.8The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and dire...
CVE-2026-49193HIGH7.5Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the...
CVE-2026-49192MEDIUM5.4The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware seri...
CVE-2026-49191CRITICAL9.8The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose...
CVE-2026-49190HIGH8.8The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unau...
CVE-2026-50219MEDIUM5.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars...
CVE-2026-49189HIGH7.8Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke ...
CVE-2026-49188CRITICAL9.8The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for u...
CVE-2026-49187HIGH7.5The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
CVE-2026-10805MEDIUM6.7A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient ba...
CVE-2026-49186CRITICAL9.8The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe usin...
CVE-2026-49185CRITICAL9.8The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction...
CVE-2026-48681HIGH8.1OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted IS...
CVE-2026-44917MEDIUM4.9OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron...
CVE-2026-41283CRITICAL9.9OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints tha...
CVE-2026-41010HIGH8.7ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "...
CVE-2026-8829HIGH7.5HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::E...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now