2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101267 | LOW | 2.7 | — | Sep 29, 2026 | A missing permission check allowed low-privileged users with access to an event but without access to the event's orders... |
| CVE-2026-100832 | HIGH | 8.8 | — | Sep 29, 2026 | Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox ESR 115.4... |
| CVE-2026-100831 | HIGH | 8.8 | — | Sep 29, 2026 | Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and F... |
| CVE-2026-100830 | — | — | — | Sep 29, 2026 | Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100829 | — | — | — | Sep 29, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100828 | — | — | — | Sep 29, 2026 | Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 15... |
| CVE-2026-100826 | MEDIUM | 6.5 | — | Sep 29, 2026 | Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefo... |
| CVE-2026-100825 | HIGH | 8.8 | — | Sep 29, 2026 | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 15... |
| CVE-2026-100824 | HIGH | 8.8 | — | Sep 29, 2026 | Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100823 | — | — | — | Sep 29, 2026 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100822 | — | — | — | Sep 29, 2026 | Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100821 | — | — | — | Sep 29, 2026 | Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 15... |
| CVE-2026-100820 | HIGH | 8.8 | — | Sep 29, 2026 | Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and F... |
| CVE-2026-100819 | — | — | — | Sep 29, 2026 | Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR ... |
| CVE-2026-100818 | CRITICAL | 9.6 | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4, Fi... |
| CVE-2026-100817 | — | — | — | Sep 29, 2026 | Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100816 | — | — | — | Sep 29, 2026 | Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157... |
| CVE-2026-100815 | — | — | — | Sep 29, 2026 | Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4 and Firef... |
| CVE-2026-100814 | — | — | — | Sep 29, 2026 | Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4... |
| CVE-2026-100813 | — | — | — | Sep 29, 2026 | Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100812 | — | — | — | Sep 29, 2026 | Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100811 | — | — | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.... |
| CVE-2026-100810 | — | — | — | Sep 29, 2026 | Other issue in the DevTools component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100809 | — | — | — | Sep 29, 2026 | Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100808 | — | — | — | Sep 29, 2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now