2026 CVE Vulnerabilities

64,659 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39832CRITICAL9.1When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serializ...
CVE-2026-39831CRITICAL9.1The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did...
CVE-2026-39830CRITICAL9.1A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection...
CVE-2026-39829HIGH7.5The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessive...
CVE-2026-39828MEDIUM6.3When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were...
CVE-2026-39827MEDIUM6.5An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory gr...
CVE-2026-9264CRITICAL9.3A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution an...
CVE-2026-34911HIGH7.7A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in Un...
CVE-2026-34910CRITICAL10A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS ...
CVE-2026-34909CRITICAL10A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a...
CVE-2026-34908CRITICAL10A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de...
CVE-2026-33000CRITICAL9.1A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit...
CVE-2026-5297——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8435MEDIUM6.5Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file appr...
CVE-2026-8434HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc...
CVE-2026-8433HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc...
CVE-2026-8432HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star...
CVE-2026-8427HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file remo...
CVE-2026-8416HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addF...
CVE-2026-8415HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/as...
CVE-2026-8414HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/dupl...
CVE-2026-8413HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/...
CVE-2026-8412HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk...
CVE-2026-8411HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/...
CVE-2026-8410HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now