2026 CVE Vulnerabilities
67,228 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-83603 | HIGH | 8.4 | 0.3% | Sep 22, 2026 | Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-sta... |
| CVE-2026-83602 | MEDIUM | 6.5 | — | Sep 22, 2026 | Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api... |
| CVE-2026-83601 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENS... |
| CVE-2026-83600 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART ... |
| CVE-2026-83599 | HIGH | 7.5 | 0.7% | Sep 22, 2026 | Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates per... |
| CVE-2026-83598 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powe... |
| CVE-2026-76819 | — | — | — | Sep 22, 2026 | Rejected reason: Further research determined the issue results from a dependency. |
| CVE-2026-76805 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path ... |
| CVE-2026-76804 | MEDIUM | 5.5 | — | Sep 22, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loadi... |
| CVE-2026-76803 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript... |
| CVE-2026-76802 | MEDIUM | 4.7 | 0.2% | Sep 22, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading b... |
| CVE-2026-56682 | MEDIUM | 5.3 | — | Sep 22, 2026 | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without ... |
| CVE-2026-13087 | — | — | 0.5% | Sep 22, 2026 | Rejected reason: This CVE was reserved in error and duplicates CVE-2026-89530. |
| CVE-2026-95806 | HIGH | 7.7 | — | Sep 22, 2026 | MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar... |
| CVE-2026-95805 | MEDIUM | 5.3 | — | Sep 22, 2026 | A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action t... |
| CVE-2026-95655 | HIGH | 8.1 | — | Sep 22, 2026 | Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated use... |
| CVE-2026-95654 | HIGH | 7.4 | 0.5% | Sep 22, 2026 | Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization de... |
| CVE-2026-95653 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead... |
| CVE-2026-94640 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (... |
| CVE-2026-92706 | LOW | 3.4 | 0.2% | Sep 22, 2026 | Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can caus... |
| CVE-2026-90462 | MEDIUM | 5.4 | — | Sep 22, 2026 | A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `... |
| CVE-2026-88010 | MEDIUM | 6.3 | 0.7% | Sep 22, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewar... |
| CVE-2026-86805 | MEDIUM | 6.3 | — | Sep 22, 2026 | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versio... |
| CVE-2026-86698 | LOW | 2.3 | — | Sep 22, 2026 | Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization me... |
| CVE-2026-85055 | HIGH | 7.1 | 0.4% | Sep 22, 2026 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now