2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-76978HIGH8.8ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection...
CVE-2026-75825HIGH8.8ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable ...
CVE-2026-19599CRITICAL9.9ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability...
CVE-2026-96446MEDIUM4.2A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent au...
CVE-2026-96445MEDIUM6.8A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue...
CVE-2026-87022HIGH7.5Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling wh...
CVE-2026-86350CRITICAL9.1Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused...
CVE-2026-86248CRITICAL9.8CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apac...
CVE-2026-84791HIGH7.1ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Con...
CVE-2026-84789HIGH7.1ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Con...
CVE-2026-84787HIGH8.1ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalat...
CVE-2026-80444MEDIUM5.4URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data M...
CVE-2026-79677HIGH7.5Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allo...
CVE-2026-78437HIGH7.3Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause on...
CVE-2026-78383HIGH7.5Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP reques...
CVE-2026-78253LOW2.3Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of servi...
CVE-2026-77791HIGH7.5Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS...
CVE-2026-77762HIGH8.1Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc...
CVE-2026-77756LOW3.7Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused b...
CVE-2026-76183CRITICAL9.8Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocke...
CVE-2026-75973HIGH7.3Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfig...
CVE-2026-73581MEDIUM6.5Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implement...
CVE-2026-15358HIGH7.5ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unautho...
CVE-2026-14913HIGH8.8ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vu...
CVE-2026-12370HIGH7.6ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now