2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-68536CRITICAL9.8Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affect...
CVE-2026-92720CRITICAL9.1Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated a...
CVE-2026-92717CRITICAL9.1Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated call...
CVE-2026-92716CRITICAL9.6Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint tha...
CVE-2026-51990CRITICAL9.8An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary ...
CVE-2026-92398CRITICAL9.1A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality o...
CVE-2026-85385CRITICAL9.6Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output en...
CVE-2026-76420CRITICAL9A vulnerability in the internal configuration of the Apache JServ Protocol (AJP)&nbsp;connector for Cisco Secure FMC Sof...
CVE-2026-20331CRITICAL9.6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl...
CVE-2026-20307CRITICAL9.9A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to exec...
CVE-2026-20306CRITICAL9.1A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform comman...
CVE-2026-20305CRITICAL9.1A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perfor...
CVE-2026-20234CRITICAL9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE...
CVE-2026-92397CRITICAL9.1A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc...
CVE-2026-90999CRITICAL9.8Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled tele...
CVE-2026-70416CRITICAL9.8Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthentica...
CVE-2026-92395CRITICAL9.1@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and i...
CVE-2026-77411CRITICAL9.5RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil...
CVE-2026-77408CRITICAL9.1RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte le...
CVE-2026-77405CRITICAL9.4RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values wit...
CVE-2026-91843CRITICAL9.8A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root...
CVE-2026-73172CRITICAL9.3Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2026-58147CRITICAL9.3WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password cha...
CVE-2026-58146CRITICAL9.4WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the ...
CVE-2026-40855CRITICAL9.3WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now