2026 CVE Vulnerabilities
65,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78609 | MEDIUM | 5.4 | 0.1% | Sep 2, 2026 | Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via... |
| CVE-2026-78602 | MEDIUM | 5.3 | 0.4% | Sep 2, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead ... |
| CVE-2026-78601 | MEDIUM | 5.5 | — | Sep 2, 2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authori... |
| CVE-2026-78599 | MEDIUM | 6.5 | — | Sep 2, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can ... |
| CVE-2026-78598 | MEDIUM | 5.4 | — | Sep 2, 2026 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiti... |
| CVE-2026-78594 | MEDIUM | 4.9 | 0.3% | Sep 2, 2026 | Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Exces... |
| CVE-2026-78591 | MEDIUM | 6.3 | — | Sep 2, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can ... |
| CVE-2026-78588 | MEDIUM | 6.5 | 0.3% | Sep 2, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive... |
| CVE-2026-78586 | MEDIUM | 6.5 | — | Sep 2, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A... |
| CVE-2026-78584 | MEDIUM | 4.3 | — | Sep 2, 2026 | Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query Sys... |
| CVE-2026-78153 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against ... |
| CVE-2026-77794 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calcu... |
| CVE-2026-77793 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-si... |
| CVE-2026-2811 | MEDIUM | 5.4 | 0.2% | Sep 2, 2026 | The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input saniti... |
| CVE-2026-2688 | MEDIUM | 6.5 | 0.2% | Sep 2, 2026 | The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter along... |
| CVE-2026-17563 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing ... |
| CVE-2026-14255 | MEDIUM | 5.5 | 0.1% | Sep 2, 2026 | A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vul... |
| CVE-2026-10821 | MEDIUM | 6.6 | 0.5% | Sep 2, 2026 | The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before w... |
| CVE-2026-81269 | MEDIUM | 5.3 | 0.3% | Sep 2, 2026 | Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field version... |
| CVE-2026-81205 | MEDIUM | 5.3 | 0.3% | Sep 2, 2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Acti... |
| CVE-2026-81201 | MEDIUM | 6.1 | 0.3% | Sep 2, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Men... |
| CVE-2026-81167 | MEDIUM | 4.8 | 0.2% | Sep 2, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Sug... |
| CVE-2026-81166 | MEDIUM | 5.3 | 0.3% | Sep 2, 2026 | Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Dig... |
| CVE-2026-81165 | MEDIUM | 5.3 | 0.3% | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from ... |
| CVE-2026-81164 | MEDIUM | 5.4 | — | Sep 2, 2026 | Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF version... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now