2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87525 | LOW | 2.7 | 0.1% | Sep 9, 2026 | Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read ... |
| CVE-2026-87521 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the ren... |
| CVE-2026-87517 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social e... |
| CVE-2026-87498 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the... |
| CVE-2026-87485 | LOW | 3.1 | 0.3% | Sep 9, 2026 | Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised th... |
| CVE-2026-87456 | LOW | 3.4 | 0.2% | Sep 9, 2026 | Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised th... |
| CVE-2026-87452 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compr... |
| CVE-2026-87451 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the ... |
| CVE-2026-87442 | LOW | 3.1 | 0.3% | Sep 9, 2026 | Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the r... |
| CVE-2026-87434 | LOW | 3.1 | 0.3% | Sep 9, 2026 | Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the ... |
| CVE-2026-86564 | LOW | 3.3 | 0.1% | Sep 8, 2026 | A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queu... |
| CVE-2026-75726 | LOW | 3.5 | 0.4% | Sep 8, 2026 | Adobe Experience Manager is affected by an Improper Input Validation vulnerability that could result in a Security featu... |
| CVE-2026-55290 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lea... |
| CVE-2026-49895 | LOW | 3.5 | 0.1% | Sep 8, 2026 | In get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bo... |
| CVE-2026-45525 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In multiple locations, there is a possible improper data sanitization due to a logic error in the code. This could lead ... |
| CVE-2026-45521 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This co... |
| CVE-2026-45519 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a conf... |
| CVE-2026-28671 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This coul... |
| CVE-2026-28660 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could le... |
| CVE-2026-28652 | LOW | 3.1 | 0.2% | Sep 8, 2026 | In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check. This could... |
| CVE-2026-28638 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the ... |
| CVE-2026-28630 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This cou... |
| CVE-2026-28623 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to ... |
| CVE-2026-28622 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permiss... |
| CVE-2026-28582 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of devi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now