2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17636 | HIGH | 8.8 | 0.7% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbi... |
| CVE-2026-17635 | CRITICAL | 9.1 | 0.5% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actio... |
| CVE-2026-17620 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260... |
| CVE-2026-17618 | HIGH | 7.3 | 0.4% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and m... |
| CVE-2026-17472 | CRITICAL | 9.6 | 0.4% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources d... |
| CVE-2026-17465 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper... |
| CVE-2026-17102 | HIGH | 8.8 | 0.6% | Sep 22, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-16672 | HIGH | 8.8 | 0.5% | Sep 22, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to... |
| CVE-2026-16469 | HIGH | 8.8 | 0.9% | Sep 22, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary ... |
| CVE-2026-16468 | HIGH | 8.8 | 1.7% | Sep 22, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-16426 | MEDIUM | 6.5 | 0.3% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated att... |
| CVE-2026-16346 | CRITICAL | 9.9 | 0.6% | Sep 22, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-15915 | MEDIUM | 6.2 | 0.2% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of... |
| CVE-2026-96269 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symb... |
| CVE-2026-96260 | MEDIUM | 6.5 | 0.4% | Sep 22, 2026 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request ... |
| CVE-2026-96259 | MEDIUM | 5.5 | 0.3% | Sep 22, 2026 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal... |
| CVE-2026-95815 | MEDIUM | 6.3 | 0.2% | Sep 22, 2026 | OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as pub... |
| CVE-2026-95814 | HIGH | 8.1 | 0.4% | Sep 22, 2026 | Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries,... |
| CVE-2026-95813 | MEDIUM | 6.1 | 0.3% | Sep 22, 2026 | e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and co... |
| CVE-2026-95812 | MEDIUM | 6.1 | 0.4% | Sep 22, 2026 | ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper functi... |
| CVE-2026-94450 | HIGH | 7.5 | 1.9% | Sep 22, 2026 | Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated ... |
| CVE-2026-91018 | HIGH | 8.8 | 0.4% | Sep 22, 2026 | lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or ... |
| CVE-2026-89019 | — | — | — | Sep 22, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-88020 | MEDIUM | 6.1 | 0.3% | Sep 22, 2026 | Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability ... |
| CVE-2026-77987 | CRITICAL | 9.8 | 0.9% | Sep 22, 2026 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. Th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now