2026 CVE Vulnerabilities
67,222 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61570 | HIGH | 7.5 | 0.3% | Sep 22, 2026 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 ... |
| CVE-2026-59991 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDI... |
| CVE-2026-58268 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_s... |
| CVE-2026-47116 | CRITICAL | 9.8 | 0.5% | Sep 22, 2026 | LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stor... |
| CVE-2026-28325 | HIGH | 8.8 | 1.5% | Sep 22, 2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability ... |
| CVE-2026-28324 | CRITICAL | 9.8 | 0.7% | Sep 22, 2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability ... |
| CVE-2026-95862 | HIGH | 7.5 | — | Sep 22, 2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi g... |
| CVE-2026-95861 | HIGH | 7.5 | — | Sep 22, 2026 | A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniF... |
| CVE-2026-95831 | HIGH | 7.8 | 0.1% | Sep 22, 2026 | Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfu... |
| CVE-2026-94462 | HIGH | 7.1 | 0.4% | Sep 22, 2026 | Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/st... |
| CVE-2026-91130 | CRITICAL | 9.3 | 0.5% | Sep 22, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Stat... |
| CVE-2026-91129 | MEDIUM | 5.4 | 0.2% | Sep 22, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP ... |
| CVE-2026-89277 | MEDIUM | 5.5 | 0.3% | Sep 22, 2026 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati... |
| CVE-2026-88415 | HIGH | 8.7 | 0.2% | Sep 22, 2026 | MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content field `contentDetails` ... |
| CVE-2026-88414 | CRITICAL | 9.8 | 0.2% | Sep 22, 2026 | MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/ver... |
| CVE-2026-84396 | MEDIUM | 5.5 | 0.1% | Sep 22, 2026 | InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-s... |
| CVE-2026-84395 | HIGH | 7.1 | — | Sep 22, 2026 | Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation... |
| CVE-2026-83964 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive... |
| CVE-2026-83963 | HIGH | 7.8 | 0.1% | Sep 22, 2026 | Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution ... |
| CVE-2026-83962 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code exe... |
| CVE-2026-82000 | CRITICAL | 9.6 | — | Sep 22, 2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i... |
| CVE-2026-81999 | HIGH | 8.7 | — | Sep 22, 2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i... |
| CVE-2026-81998 | HIGH | 7.8 | 0.1% | Sep 22, 2026 | Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution ... |
| CVE-2026-81995 | CRITICAL | 9.1 | — | Sep 22, 2026 | Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitr... |
| CVE-2026-79906 | HIGH | 7.8 | 0.1% | Sep 22, 2026 | Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now