2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30905HIGH7.8External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11...
CVE-2026-30904MEDIUM4.3Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a...
CVE-2026-22677MEDIUM6.5Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authent...
CVE-2026-0262HIGH7.5Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with...
CVE-2026-0261HIGH7.2Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator ...
CVE-2026-0259HIGH8.8An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables u...
CVE-2026-0258CRITICAL9.1A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software al...
CVE-2026-0257CRITICAL9.1Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software all...
CVE-2026-0256MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticat...
CVE-2026-0251HIGH7.8Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to e...
CVE-2026-0250HIGH8.1A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle att...
CVE-2026-0249MEDIUM6.5Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacke...
CVE-2026-0248MEDIUM5.9An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attack...
CVE-2026-0247HIGH7.8Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attack...
CVE-2026-0246HIGH7.8A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally a...
CVE-2026-0245MEDIUM5.5Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configura...
CVE-2026-0244HIGH8.1An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (...
CVE-2026-0242MEDIUM6.1A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL c...
CVE-2026-0241HIGH7.2Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and per...
CVE-2026-0240HIGH8.7An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensi...
CVE-2026-0239MEDIUM6.5An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with net...
CVE-2026-0238LOW3.2A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into c...
CVE-2026-0236HIGH7.8A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its A...
CVE-2026-0235MEDIUM4.7A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to b...
CVE-2026-45411CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield*...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now