2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76978 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection... |
| CVE-2026-75825 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable ... |
| CVE-2026-19599 | CRITICAL | 9.9 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability... |
| CVE-2026-96446 | MEDIUM | 4.2 | 0.2% | Sep 23, 2026 | A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent au... |
| CVE-2026-96445 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue... |
| CVE-2026-87022 | HIGH | 7.5 | — | Sep 23, 2026 | Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling wh... |
| CVE-2026-86350 | CRITICAL | 9.1 | — | Sep 23, 2026 | Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused... |
| CVE-2026-86248 | CRITICAL | 9.8 | — | Sep 23, 2026 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apac... |
| CVE-2026-84791 | HIGH | 7.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Con... |
| CVE-2026-84789 | HIGH | 7.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Con... |
| CVE-2026-84787 | HIGH | 8.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalat... |
| CVE-2026-80444 | MEDIUM | 5.4 | — | Sep 23, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data M... |
| CVE-2026-79677 | HIGH | 7.5 | — | Sep 23, 2026 | Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allo... |
| CVE-2026-78437 | HIGH | 7.3 | — | Sep 23, 2026 | Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause on... |
| CVE-2026-78383 | HIGH | 7.5 | — | Sep 23, 2026 | Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP reques... |
| CVE-2026-78253 | LOW | 2.3 | 0.3% | Sep 23, 2026 | Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of servi... |
| CVE-2026-77791 | HIGH | 7.5 | — | Sep 23, 2026 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS... |
| CVE-2026-77762 | HIGH | 8.1 | 0.4% | Sep 23, 2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc... |
| CVE-2026-77756 | LOW | 3.7 | — | Sep 23, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused b... |
| CVE-2026-76183 | CRITICAL | 9.8 | 0.4% | Sep 23, 2026 | Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocke... |
| CVE-2026-75973 | HIGH | 7.3 | — | Sep 23, 2026 | Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfig... |
| CVE-2026-73581 | MEDIUM | 6.5 | 0.1% | Sep 23, 2026 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implement... |
| CVE-2026-15358 | HIGH | 7.5 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unautho... |
| CVE-2026-14913 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vu... |
| CVE-2026-12370 | HIGH | 7.6 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now