2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17273 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL poin... |
| CVE-2026-17270 | MEDIUM | 5.5 | 0.2% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overf... |
| CVE-2026-17259 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-bas... |
| CVE-2026-16941 | MEDIUM | 4.3 | 0.2% | Sep 4, 2026 | IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper au... |
| CVE-2026-16892 | MEDIUM | 5.4 | 0.3% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper... |
| CVE-2026-16693 | MEDIUM | 4.9 | 0.1% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use ... |
| CVE-2026-16689 | MEDIUM | 5.5 | 0.1% | Sep 4, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1... |
| CVE-2026-16660 | MEDIUM | 5.3 | 0.4% | Sep 4, 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bound... |
| CVE-2026-16180 | MEDIUM | 5.7 | 0.2% | Sep 4, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1... |
| CVE-2026-14470 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An at... |
| CVE-2026-14350 | MEDIUM | 5.3 | 0.3% | Sep 4, 2026 | IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log ... |
| CVE-2026-82911 | MEDIUM | 5.1 | 0.2% | Sep 4, 2026 | Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero ... |
| CVE-2026-78970 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An auth... |
| CVE-2026-78658 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 throug... |
| CVE-2026-75170 | MEDIUM | 6.1 | 0.2% | Sep 4, 2026 | Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.... |
| CVE-2026-75168 | MEDIUM | 6.3 | 0.3% | Sep 4, 2026 | An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a r... |
| CVE-2026-75167 | MEDIUM | 4.3 | 0.2% | Sep 4, 2026 | A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway... |
| CVE-2026-75165 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user wi... |
| CVE-2026-75164 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allo... |
| CVE-2026-75163 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gat... |
| CVE-2026-75162 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Seri... |
| CVE-2026-5522 | MEDIUM | 6.7 | 0.1% | Sep 4, 2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic... |
| CVE-2026-19649 | MEDIUM | 5.5 | 0.1% | Sep 4, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1... |
| CVE-2026-19645 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily... |
| CVE-2026-19302 | MEDIUM | 6.5 | 0.5% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now