2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-92717CRITICAL9.1Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated call...
CVE-2026-92716CRITICAL9.6Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint tha...
CVE-2026-51990CRITICAL9.8An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary ...
CVE-2026-92398CRITICAL9.1A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality o...
CVE-2026-85385CRITICAL9.6Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output en...
CVE-2026-76420CRITICAL9A vulnerability in the internal configuration of the Apache JServ Protocol (AJP)&nbsp;connector for Cisco Secure FMC Sof...
CVE-2026-20331CRITICAL9.6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl...
CVE-2026-20307CRITICAL9.9A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to exec...
CVE-2026-20306CRITICAL9.1A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform comman...
CVE-2026-20305CRITICAL9.1A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perfor...
CVE-2026-20234CRITICAL9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE...
CVE-2026-92397CRITICAL9.1A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc...
CVE-2026-90999CRITICAL9.8Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled tele...
CVE-2026-70416CRITICAL9.8Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthentica...
CVE-2026-92395CRITICAL9.1@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and i...
CVE-2026-77411CRITICAL9.5RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil...
CVE-2026-77408CRITICAL9.1RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte le...
CVE-2026-77405CRITICAL9.4RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values wit...
CVE-2026-91843CRITICAL9.8A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root...
CVE-2026-73172CRITICAL9.3Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2026-58147CRITICAL9.3WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password cha...
CVE-2026-58146CRITICAL9.4WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the ...
CVE-2026-40855CRITICAL9.3WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality ...
CVE-2026-90049CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in...
CVE-2026-90048CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now