2026 CVE Vulnerabilities
61,930 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48827 | HIGH | 7.1 | 0.5% | Jun 1, 2026 | Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receiv... |
| CVE-2026-48726 | MEDIUM | 6.5 | 0.4% | Jun 1, 2026 | A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked lo... |
| CVE-2026-46764 | MEDIUM | 4.3 | 0.4% | Jun 1, 2026 | The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly b... |
| CVE-2026-46605 | MEDIUM | 4.3 | 0.3% | Jun 1, 2026 | Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections t... |
| CVE-2026-45505 | HIGH | 8.8 | 0.6% | Jun 1, 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br... |
| CVE-2026-45426 | LOW | 3.1 | 0.3% | Jun 1, 2026 | Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued f... |
| CVE-2026-45360 | HIGH | 7.3 | 0.7% | Jun 1, 2026 | Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported ... |
| CVE-2026-44825 | CRITICAL | 9.8 | 0.5% | Jun 1, 2026 | Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 throug... |
| CVE-2026-42588 | HIGH | 8.1 | 0.5% | Jun 1, 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br... |
| CVE-2026-42360 | MEDIUM | 6.5 | 0.3% | Jun 1, 2026 | A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` /... |
| CVE-2026-42359 | HIGH | 8.8 | 0.5% | Jun 1, 2026 | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user wit... |
| CVE-2026-42358 | MEDIUM | 6.5 | 0.3% | Jun 1, 2026 | A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names l... |
| CVE-2026-42253 | MEDIUM | 6.1 | 1.1% | Jun 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A... |
| CVE-2026-42252 | CRITICAL | 9.1 | 0.4% | Jun 1, 2026 | Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") show... |
| CVE-2026-41084 | HIGH | 7.5 | 0.5% | Jun 1, 2026 | A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstance... |
| CVE-2026-41017 | MEDIUM | 5.9 | 0.3% | Jun 1, 2026 | Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai... |
| CVE-2026-41014 | MEDIUM | 4.3 | 0.4% | Jun 1, 2026 | The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization... |
| CVE-2026-40963 | LOW | 3.1 | 0.5% | Jun 1, 2026 | The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking ... |
| CVE-2026-40961 | HIGH | 7.2 | 0.6% | Jun 1, 2026 | A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe... |
| CVE-2026-40861 | MEDIUM | 6.5 | 0.7% | Jun 1, 2026 | A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable b... |
| CVE-2026-40549 | MEDIUM | 5.1 | 0.2% | Jun 1, 2026 | SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An att... |
| CVE-2026-40548 | MEDIUM | 6.4 | 0.3% | Jun 1, 2026 | SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality ca... |
| CVE-2026-40547 | MEDIUM | 6.4 | 0.4% | Jun 1, 2026 | SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vuln... |
| CVE-2026-40546 | HIGH | 8.7 | 0.2% | Jun 1, 2026 | SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inj... |
| CVE-2026-40545 | MEDIUM | 5.1 | 0.4% | Jun 1, 2026 | SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when op... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now