2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92717 | CRITICAL | 9.1 | 0.4% | Sep 16, 2026 | Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated call... |
| CVE-2026-92716 | CRITICAL | 9.6 | 0.4% | Sep 16, 2026 | Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint tha... |
| CVE-2026-51990 | CRITICAL | 9.8 | 1.0% | Sep 16, 2026 | An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary ... |
| CVE-2026-92398 | CRITICAL | 9.1 | — | Sep 16, 2026 | A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality o... |
| CVE-2026-85385 | CRITICAL | 9.6 | 0.4% | Sep 16, 2026 | Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output en... |
| CVE-2026-76420 | CRITICAL | 9 | — | Sep 16, 2026 | A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Sof... |
| CVE-2026-20331 | CRITICAL | 9.6 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl... |
| CVE-2026-20307 | CRITICAL | 9.9 | — | Sep 16, 2026 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to exec... |
| CVE-2026-20306 | CRITICAL | 9.1 | — | Sep 16, 2026 | A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform comman... |
| CVE-2026-20305 | CRITICAL | 9.1 | — | Sep 16, 2026 | A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perfor... |
| CVE-2026-20234 | CRITICAL | 9.9 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE... |
| CVE-2026-92397 | CRITICAL | 9.1 | — | Sep 16, 2026 | A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc... |
| CVE-2026-90999 | CRITICAL | 9.8 | — | Sep 16, 2026 | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled tele... |
| CVE-2026-70416 | CRITICAL | 9.8 | 0.9% | Sep 16, 2026 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthentica... |
| CVE-2026-92395 | CRITICAL | 9.1 | — | Sep 16, 2026 | @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and i... |
| CVE-2026-77411 | CRITICAL | 9.5 | 0.4% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil... |
| CVE-2026-77408 | CRITICAL | 9.1 | 0.4% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte le... |
| CVE-2026-77405 | CRITICAL | 9.4 | 0.3% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values wit... |
| CVE-2026-91843 | CRITICAL | 9.8 | — | Sep 16, 2026 | A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root... |
| CVE-2026-73172 | CRITICAL | 9.3 | 1.7% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-58147 | CRITICAL | 9.3 | — | Sep 16, 2026 | WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password cha... |
| CVE-2026-58146 | CRITICAL | 9.4 | — | Sep 16, 2026 | WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the ... |
| CVE-2026-40855 | CRITICAL | 9.3 | — | Sep 16, 2026 | WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality ... |
| CVE-2026-90049 | CRITICAL | 9.3 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in... |
| CVE-2026-90048 | CRITICAL | 9.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now