2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6389HIGH7.8IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cl...
CVE-2026-40687CRITICAL9.1In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-...
CVE-2026-40686MEDIUM5.3In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing character...
CVE-2026-40685CRITICAL9.8In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounter...
CVE-2026-40684HIGH7.5In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malfor...
CVE-2026-3345MEDIUM6.5IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker c...
CVE-2026-2311CRITICAL9.8IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI...
CVE-2026-1577MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2026-7501LOW3.5A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/...
CVE-2026-7435HIGH8.6SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed ...
CVE-2026-6539MEDIUM4.6Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers...
CVE-2026-4503HIGH7.5IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to...
CVE-2026-4502MEDIUM6.5IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the s...
CVE-2026-41263LOW3.7Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a timing...
CVE-2026-41174MEDIUM6.4Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potent...
CVE-2026-40951MEDIUM5.5CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with loc...
CVE-2026-40950MEDIUM6.5CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of...
CVE-2026-40949MEDIUM4.4CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo...
CVE-2026-40912HIGH8.2Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s...
CVE-2026-3346MEDIUM6.4IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows...
CVE-2026-3340MEDIUM6.5IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo...
CVE-2026-39858CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s...
CVE-2026-35051CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authe...
CVE-2026-33452MEDIUM5.5CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo...
CVE-2026-33451HIGH7.8CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now