2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30905 | HIGH | 7.8 | 0.1% | May 13, 2026 | External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11... |
| CVE-2026-30904 | MEDIUM | 4.3 | 0.1% | May 13, 2026 | Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a... |
| CVE-2026-22677 | MEDIUM | 6.5 | 0.4% | May 13, 2026 | Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authent... |
| CVE-2026-0262 | HIGH | 7.5 | 0.3% | May 13, 2026 | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with... |
| CVE-2026-0261 | HIGH | 7.2 | 1.3% | May 13, 2026 | Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator ... |
| CVE-2026-0259 | HIGH | 8.8 | 0.3% | May 13, 2026 | An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables u... |
| CVE-2026-0258 | CRITICAL | 9.1 | 0.3% | May 13, 2026 | A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software al... |
| CVE-2026-0257 | CRITICAL | 9.1 | 86.7% | May 13, 2026 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software all... |
| CVE-2026-0256 | MEDIUM | 4.8 | 0.3% | May 13, 2026 | A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticat... |
| CVE-2026-0251 | HIGH | 7.8 | 0.2% | May 13, 2026 | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to e... |
| CVE-2026-0250 | HIGH | 8.1 | 0.2% | May 13, 2026 | A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle att... |
| CVE-2026-0249 | MEDIUM | 6.5 | 0.1% | May 13, 2026 | Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacke... |
| CVE-2026-0248 | MEDIUM | 5.9 | 0.1% | May 13, 2026 | An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attack... |
| CVE-2026-0247 | HIGH | 7.8 | 0.2% | May 13, 2026 | Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attack... |
| CVE-2026-0246 | HIGH | 7.8 | 0.1% | May 13, 2026 | A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally a... |
| CVE-2026-0245 | MEDIUM | 5.5 | 0.1% | May 13, 2026 | Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configura... |
| CVE-2026-0244 | HIGH | 8.1 | 0.1% | May 13, 2026 | An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (... |
| CVE-2026-0242 | MEDIUM | 6.1 | 0.2% | May 13, 2026 | A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL c... |
| CVE-2026-0241 | HIGH | 7.2 | 0.3% | May 13, 2026 | Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and per... |
| CVE-2026-0240 | HIGH | 8.7 | 0.2% | May 13, 2026 | An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensi... |
| CVE-2026-0239 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with net... |
| CVE-2026-0238 | LOW | 3.2 | 0.1% | May 13, 2026 | A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into c... |
| CVE-2026-0236 | HIGH | 7.8 | 0.1% | May 13, 2026 | A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its A... |
| CVE-2026-0235 | MEDIUM | 4.7 | 0.2% | May 13, 2026 | A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to b... |
| CVE-2026-45411 | CRITICAL | 9.8 | 0.6% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield*... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now