2026 CVE Vulnerabilities

67,199 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-84718MEDIUM4.3A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the ...
CVE-2026-84717MEDIUM5.3A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center web...
CVE-2026-84716MEDIUM6.6A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administ...
CVE-2026-84714HIGH7.1A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function us...
CVE-2026-84713MEDIUM6.5A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.no...
CVE-2026-84712MEDIUM5.3A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/p...
CVE-2026-84706HIGH7.6A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable...
CVE-2026-84691HIGH8.7A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log messa...
CVE-2026-84683HIGH8.7A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, ...
CVE-2026-82409HIGH8.4Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataF...
CVE-2026-82407HIGH7Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.g...
CVE-2026-82406HIGH7.1Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function c...
CVE-2026-82405HIGH8.7Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission...
CVE-2026-75884CRITICAL9.1A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts au...
CVE-2026-68492HIGH8.7An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote...
CVE-2026-68490HIGH8.2Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other acc...
CVE-2026-67238HIGH7.1RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, rabbit_pid_codec:decompose_from_binary/...
CVE-2026-66079HIGH8.2RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitiv...
CVE-2026-66076LOW2.3RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized...
CVE-2026-66070HIGH7.6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 retur...
CVE-2026-96872LOW2.9Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLa...
CVE-2026-96770CRITICAL9.3All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use ...
CVE-2026-96549LOW3.3A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability...
CVE-2026-96548MEDIUM5.6A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown par...
CVE-2026-96546LOW2.5A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompre...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now