2026 CVE Vulnerabilities
67,200 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77422 | HIGH | 7.5 | 0.5% | Sep 23, 2026 | JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command ... |
| CVE-2026-77421 | MEDIUM | 6.5 | 0.4% | Sep 23, 2026 | JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's... |
| CVE-2026-77420 | MEDIUM | 5.5 | 0.1% | Sep 23, 2026 | JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(Str... |
| CVE-2026-77394 | HIGH | 7.6 | — | Sep 23, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-77285 | LOW | 2.4 | 0.1% | Sep 23, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode ... |
| CVE-2026-76648 | HIGH | 8.5 | 0.2% | Sep 23, 2026 | CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs n... |
| CVE-2026-76089 | HIGH | 7.7 | 0.2% | Sep 23, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-rese... |
| CVE-2026-76087 | HIGH | 8.2 | 0.3% | Sep 23, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submi... |
| CVE-2026-76086 | HIGH | 8.5 | 0.3% | Sep 23, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings ... |
| CVE-2026-75131 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local use... |
| CVE-2026-71465 | LOW | 3.1 | 0.2% | Sep 23, 2026 | RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using ... |
| CVE-2026-71464 | LOW | 3.1 | 0.2% | Sep 23, 2026 | LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike ... |
| CVE-2026-71463 | LOW | 2.7 | 0.3% | Sep 23, 2026 | Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job... |
| CVE-2026-71462 | MEDIUM | 4.1 | — | Sep 23, 2026 | StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. ... |
| CVE-2026-71461 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated use... |
| CVE-2026-71460 | MEDIUM | 4.3 | — | Sep 23, 2026 | /api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_... |
| CVE-2026-71459 | MEDIUM | 5 | 0.3% | Sep 23, 2026 | JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() ... |
| CVE-2026-71458 | MEDIUM | 5 | — | Sep 23, 2026 | URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403... |
| CVE-2026-63132 | CRITICAL | 9.2 | 0.5% | Sep 23, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path... |
| CVE-2026-63131 | MEDIUM | 6 | 0.4% | Sep 23, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could ... |
| CVE-2026-61814 | HIGH | 7.5 | 0.6% | Sep 23, 2026 | Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON tok... |
| CVE-2026-61695 | HIGH | 7.5 | 0.6% | Sep 23, 2026 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's S... |
| CVE-2026-59990 | HIGH | 7.5 | 0.6% | Sep 23, 2026 | Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nes... |
| CVE-2026-55632 | MEDIUM | 4.3 | 0.3% | Sep 23, 2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompleti... |
| CVE-2026-55456 | — | — | — | Sep 23, 2026 | Rejected reason: This CVE is a duplicate of another CVE. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now