2026 CVE Vulnerabilities
67,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34689 | HIGH | 8.6 | 0.7% | Sep 22, 2026 | Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabi... |
| CVE-2026-19480 | HIGH | 7.5 | — | Sep 22, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur... |
| CVE-2026-95660 | MEDIUM | 6.3 | — | Sep 22, 2026 | A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function o... |
| CVE-2026-95657 | LOW | 3.5 | 0.4% | Sep 22, 2026 | A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSe... |
| CVE-2026-95656 | HIGH | 7.3 | — | Sep 22, 2026 | A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_wat... |
| CVE-2026-95624 | MEDIUM | 6.8 | — | Sep 22, 2026 | The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaS... |
| CVE-2026-94384 | HIGH | 8.1 | — | Sep 22, 2026 | Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:Invoke... |
| CVE-2026-93345 | HIGH | 7.5 | 0.5% | Sep 22, 2026 | MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterator... |
| CVE-2026-8849 | HIGH | 7.7 | — | Sep 22, 2026 | Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects... |
| CVE-2026-89276 | CRITICAL | 9.9 | 0.5% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t... |
| CVE-2026-89275 | CRITICAL | 10 | 1.2% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t... |
| CVE-2026-86056 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/... |
| CVE-2026-86054 | HIGH | 7.8 | — | Sep 22, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in Np... |
| CVE-2026-85995 | HIGH | 7.3 | 0.1% | Sep 22, 2026 | Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature veri... |
| CVE-2026-85288 | MEDIUM | 6.7 | 0.1% | Sep 22, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HM... |
| CVE-2026-85279 | HIGH | 8.6 | 0.2% | Sep 22, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in Pl... |
| CVE-2026-84412 | CRITICAL | 10 | 1.2% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t... |
| CVE-2026-83660 | CRITICAL | 10 | 0.3% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv... |
| CVE-2026-83597 | HIGH | 7 | 0.1% | Sep 22, 2026 | Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches... |
| CVE-2026-82443 | CRITICAL | 9.9 | 0.7% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv... |
| CVE-2026-82013 | CRITICAL | 9.9 | 0.8% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv... |
| CVE-2026-82011 | CRITICAL | 9.1 | 0.6% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-82010 | CRITICAL | 9.9 | 1.0% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-82009 | CRITICAL | 9.1 | 1.0% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-82008 | CRITICAL | 9.9 | 1.2% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now