2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0243MEDIUM6.5A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attac...
CVE-2026-8496MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar in...
CVE-2026-8466HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbo...
CVE-2026-44248HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT ...
CVE-2026-43970HIGH8.2Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticate...
CVE-2026-42587HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpConte...
CVE-2026-42586HIGH7.1Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty...
CVE-2026-42585HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty inc...
CVE-2026-42584CRITICAL9.1Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClien...
CVE-2026-42583HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameD...
CVE-2026-42582HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks...
CVE-2026-42581CRITICAL9.8Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjec...
CVE-2026-42580MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's c...
CVE-2026-42579CRITICAL9.1Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's D...
CVE-2026-42578HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's H...
CVE-2026-42577HIGH7.5Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll t...
CVE-2026-42032CRITICAL9.1CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-42031CRITICAL9.8CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-41410——Rejected reason: REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-40520. Reason: This candidate is a dup...
CVE-2026-41255MEDIUM6.1CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-41132HIGH7.4CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-33585LOW3.8Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacke...
CVE-2026-33584MEDIUM5.3Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensit...
CVE-2026-33583HIGH8.7Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via a...
CVE-2026-30906HIGH7.8Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now