2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-89783CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr(...
CVE-2026-89779CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's nam...
CVE-2026-89778CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty...
CVE-2026-89775CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR ...
CVE-2026-86462CRITICAL9.1Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate t...
CVE-2026-82717CRITICAL9.8In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memor...
CVE-2026-82311CRITICAL9.8Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, ...
CVE-2026-81642CRITICAL9.8In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial ...
CVE-2026-27565CRITICAL9.8An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root pr...
CVE-2026-27546CRITICAL9.8An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an adm...
CVE-2026-73447CRITICAL9.1A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full ...
CVE-2026-14349CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ...
CVE-2026-12793CRITICAL9.8The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versi...
CVE-2026-15640CRITICAL9.5Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
CVE-2026-15639CRITICAL9.3An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScrip...
CVE-2026-15638CRITICAL9.1An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using on...
CVE-2026-81855CRITICAL9.1A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wär...
CVE-2026-78225CRITICAL9A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS...
CVE-2026-73807CRITICAL9.8The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthentica...
CVE-2026-73437CRITICAL9.6On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenti...
CVE-2026-61560CRITICAL9.8`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`...
CVE-2026-91939CRITICAL9.8Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing...
CVE-2026-91749CRITICAL9.6Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbit...
CVE-2026-91738CRITICAL9.6Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially exec...
CVE-2026-91729CRITICAL9.6Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now