2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62998 | MEDIUM | 4.3 | — | Sep 23, 2026 | REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.... |
| CVE-2026-61834 | MEDIUM | 4.3 | — | Sep 23, 2026 | scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and as... |
| CVE-2026-61413 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Managemen... |
| CVE-2026-55610 | HIGH | 8.7 | — | Sep 23, 2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and... |
| CVE-2026-96560 | CRITICAL | 9.8 | — | Sep 23, 2026 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_t... |
| CVE-2026-96559 | — | — | — | Sep 23, 2026 | Rejected reason: This ID was for testing |
| CVE-2026-96512 | HIGH | 7.8 | 0.1% | Sep 23, 2026 | A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps th... |
| CVE-2026-86708 | CRITICAL | 10 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud servi... |
| CVE-2026-86683 | HIGH | 8.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy s... |
| CVE-2026-86681 | HIGH | 7.6 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue t... |
| CVE-2026-86679 | HIGH | 7.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue t... |
| CVE-2026-86678 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administ... |
| CVE-2026-86677 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized S... |
| CVE-2026-59167 | CRITICAL | 10 | 0.4% | Sep 23, 2026 | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the... |
| CVE-2026-18179 | MEDIUM | 6.5 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions... |
| CVE-2026-18177 | HIGH | 7.1 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payme... |
| CVE-2026-12974 | HIGH | 7.9 | — | Sep 23, 2026 | A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Secu... |
| CVE-2026-95676 | HIGH | 7.4 | 0.5% | Sep 23, 2026 | A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authenticat... |
| CVE-2026-86247 | HIGH | 7.4 | — | Sep 23, 2026 | Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirement... |
| CVE-2026-86246 | CRITICAL | 9.1 | — | Sep 23, 2026 | Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by ... |
| CVE-2026-86243 | HIGH | 7.5 | — | Sep 23, 2026 | Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a Do... |
| CVE-2026-84091 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a... |
| CVE-2026-77112 | MEDIUM | 6.5 | — | Sep 23, 2026 | Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server S... |
| CVE-2026-76980 | HIGH | 7.4 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vul... |
| CVE-2026-76979 | HIGH | 7.7 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now