2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89783 | CRITICAL | 9.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr(... |
| CVE-2026-89779 | CRITICAL | 9.1 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's nam... |
| CVE-2026-89778 | CRITICAL | 9.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty... |
| CVE-2026-89775 | CRITICAL | 9.3 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR ... |
| CVE-2026-86462 | CRITICAL | 9.1 | 0.2% | Sep 16, 2026 | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate t... |
| CVE-2026-82717 | CRITICAL | 9.8 | 0.4% | Sep 16, 2026 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memor... |
| CVE-2026-82311 | CRITICAL | 9.8 | 0.2% | Sep 16, 2026 | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, ... |
| CVE-2026-81642 | CRITICAL | 9.8 | 0.5% | Sep 16, 2026 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial ... |
| CVE-2026-27565 | CRITICAL | 9.8 | 0.9% | Sep 16, 2026 | An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root pr... |
| CVE-2026-27546 | CRITICAL | 9.8 | 1.0% | Sep 16, 2026 | An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an adm... |
| CVE-2026-73447 | CRITICAL | 9.1 | 0.8% | Sep 16, 2026 | A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full ... |
| CVE-2026-14349 | CRITICAL | 9.8 | 0.4% | Sep 16, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ... |
| CVE-2026-12793 | CRITICAL | 9.8 | 0.4% | Sep 16, 2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versi... |
| CVE-2026-15640 | CRITICAL | 9.5 | 0.3% | Sep 16, 2026 | Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user. |
| CVE-2026-15639 | CRITICAL | 9.3 | 0.4% | Sep 16, 2026 | An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScrip... |
| CVE-2026-15638 | CRITICAL | 9.1 | 0.2% | Sep 16, 2026 | An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using on... |
| CVE-2026-81855 | CRITICAL | 9.1 | 0.6% | Sep 15, 2026 | A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wär... |
| CVE-2026-78225 | CRITICAL | 9 | 0.5% | Sep 15, 2026 | A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS... |
| CVE-2026-73807 | CRITICAL | 9.8 | 0.7% | Sep 15, 2026 | The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthentica... |
| CVE-2026-73437 | CRITICAL | 9.6 | 0.2% | Sep 15, 2026 | On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenti... |
| CVE-2026-61560 | CRITICAL | 9.8 | — | Sep 15, 2026 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`... |
| CVE-2026-91939 | CRITICAL | 9.8 | 0.6% | Sep 15, 2026 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing... |
| CVE-2026-91749 | CRITICAL | 9.6 | 0.3% | Sep 15, 2026 | Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbit... |
| CVE-2026-91738 | CRITICAL | 9.6 | 0.2% | Sep 15, 2026 | Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially exec... |
| CVE-2026-91729 | CRITICAL | 9.6 | 0.2% | Sep 15, 2026 | Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now