2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-17636HIGH8.8IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbi...
CVE-2026-17635CRITICAL9.1IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actio...
CVE-2026-17620MEDIUM5.3IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260...
CVE-2026-17618HIGH7.3IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and m...
CVE-2026-17472CRITICAL9.6IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources d...
CVE-2026-17465MEDIUM6.5IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper...
CVE-2026-17102HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-16672HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-16469HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary ...
CVE-2026-16468HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-16426MEDIUM6.5IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated att...
CVE-2026-16346CRITICAL9.9IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-15915MEDIUM6.2IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of...
CVE-2026-96269HIGH7.5GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symb...
CVE-2026-96260MEDIUM6.5Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request ...
CVE-2026-96259MEDIUM5.5Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal...
CVE-2026-95815MEDIUM6.3OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as pub...
CVE-2026-95814HIGH8.1Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries,...
CVE-2026-95813MEDIUM6.1e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and co...
CVE-2026-95812MEDIUM6.1ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper functi...
CVE-2026-94450HIGH7.5Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated ...
CVE-2026-91018HIGH8.8lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or ...
CVE-2026-89019——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-88020MEDIUM6.1Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability ...
CVE-2026-77987CRITICAL9.8A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. Th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now