2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0054 | LOW | 3.3 | 0.1% | Sep 8, 2026 | In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a mi... |
| CVE-2026-9216 | LOW | 3.5 | 0.2% | Sep 8, 2026 | An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacke... |
| CVE-2026-86670 | LOW | 3.7 | — | Sep 8, 2026 | A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/ad... |
| CVE-2026-69904 | LOW | 3.5 | 0.6% | Sep 8, 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information ... |
| CVE-2026-48707 | LOW | 3.1 | 0.2% | Sep 8, 2026 | InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forg... |
| CVE-2026-84392 | LOW | 2.7 | — | Sep 8, 2026 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all v... |
| CVE-2026-84389 | LOW | 3.1 | 0.1% | Sep 8, 2026 | A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM... |
| CVE-2026-86644 | LOW | 3.5 | — | Sep 8, 2026 | A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_s... |
| CVE-2026-73318 | LOW | 3.8 | 0.3% | Sep 8, 2026 | XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any A... |
| CVE-2026-73317 | LOW | 2.7 | 0.3% | Sep 8, 2026 | XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows lim... |
| CVE-2026-33920 | LOW | 3.5 | — | Sep 8, 2026 | A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to mis... |
| CVE-2026-16003 | LOW | 2 | 0.1% | Sep 8, 2026 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process i... |
| CVE-2026-82710 | LOW | 2.3 | 0.4% | Sep 8, 2026 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a maliciou... |
| CVE-2026-76961 | LOW | 3.5 | 0.1% | Sep 8, 2026 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on c... |
| CVE-2026-76960 | LOW | 3.5 | 0.1% | Sep 8, 2026 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on c... |
| CVE-2026-58234 | LOW | 2.2 | 0.2% | Sep 8, 2026 | SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nes... |
| CVE-2026-82584 | LOW | 2.3 | 0.3% | Sep 7, 2026 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious pa... |
| CVE-2026-81638 | LOW | 2.1 | 0.1% | Sep 7, 2026 | Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit sever... |
| CVE-2026-86505 | LOW | 3.3 | 0.1% | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace |
| CVE-2026-86503 | LOW | 3.3 | 0.1% | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source UR... |
| CVE-2026-86501 | LOW | 2.8 | 0.3% | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log |
| CVE-2026-86491 | LOW | 3.5 | 0.1% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads |
| CVE-2026-86487 | LOW | 3.1 | 0.1% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canva... |
| CVE-2026-86486 | LOW | 3.7 | 0.2% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank |
| CVE-2026-86485 | LOW | 3.3 | 0.1% | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now