2026 CVE Vulnerabilities

64,704 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9141CRITICAL9.8Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web...
CVE-2026-9139CRITICAL9.8Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web ...
CVE-2026-9137HIGH7.5The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB ...
CVE-2026-9136MEDIUM6.5A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlle...
CVE-2026-9133HIGH8.3Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws...
CVE-2026-9129CRITICAL9.4A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling ...
CVE-2026-9126HIGH8.8Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code in...
CVE-2026-9124MEDIUM5.3Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacke...
CVE-2026-9123HIGH7.5Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local ...
CVE-2026-9122MEDIUM6.5Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentiall...
CVE-2026-9121HIGH8.8Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit h...
CVE-2026-9120HIGH8.8Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code vi...
CVE-2026-9119HIGH8.8Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrar...
CVE-2026-9118HIGH8.8Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary ...
CVE-2026-9117HIGH7.5Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had comp...
CVE-2026-9116MEDIUM4.3Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker t...
CVE-2026-9115MEDIUM4.3Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker ...
CVE-2026-9114HIGH8.8Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code i...
CVE-2026-9113MEDIUM4.3Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of...
CVE-2026-9112HIGH8.8Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary...
CVE-2026-9111HIGH8.8Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrar...
CVE-2026-9110MEDIUM4.2Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had...
CVE-2026-9102CRITICAL9.4A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitiza...
CVE-2026-9082CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core...
CVE-2026-47099MEDIUM6.1TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows atta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now