2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7776HIGH7.5Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition ...
CVE-2026-7779MEDIUM4.3A security flaw has been discovered in Open5GS up to 2.7.7. Affected is the function udm_nudr_dr_handle_subscription_aut...
CVE-2026-42238CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore end...
CVE-2026-42223MEDIUM6.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/sett...
CVE-2026-42222CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exist...
CVE-2026-42221CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticate...
CVE-2026-42220MEDIUM6.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /a...
CVE-2026-7768HIGH7.5@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit ...
CVE-2026-6321HIGH7.5fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize()...
CVE-2026-41927HIGH8.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firew...
CVE-2026-41926CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cg...
CVE-2026-41925CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi bin...
CVE-2026-41924CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest...
CVE-2026-41923CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cg...
CVE-2026-41922CRITICAL9.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cg...
CVE-2026-34882——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-6074. Reason: This record is a reservation duplicate o...
CVE-2026-43964HIGH7.5Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash v...
CVE-2026-42237HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f...
CVE-2026-42236HIGH7.5n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client...
CVE-2026-42235CRITICAL9.6n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated a...
CVE-2026-42234HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use...
CVE-2026-42233CRITICAL9.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle...
CVE-2026-42232HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use...
CVE-2026-42231HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js...
CVE-2026-42230MEDIUM6.1n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/regis...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now