2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93647 | CRITICAL | 9.3 | — | Sep 25, 2026 | An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the messag... |
| CVE-2026-93643 | CRITICAL | 9.8 | — | Sep 25, 2026 | When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported p... |
| CVE-2026-93642 | CRITICAL | 9.3 | — | Sep 25, 2026 | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipie... |
| CVE-2026-93641 | CRITICAL | 9.3 | — | Sep 25, 2026 | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipi... |
| CVE-2026-100075 | CRITICAL | 9.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters... |
| CVE-2026-95832 | CRITICAL | 9.3 | — | Sep 25, 2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code h... |
| CVE-2026-92609 | CRITICAL | 9.8 | — | Sep 25, 2026 | Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticat... |
| CVE-2026-93399 | CRITICAL | 9.1 | 0.4% | Sep 25, 2026 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2... |
| CVE-2026-89055 | CRITICAL | 9.1 | — | Sep 25, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, a... |
| CVE-2026-14281 | CRITICAL | 9.8 | — | Sep 25, 2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne... |
| CVE-2026-92289 | CRITICAL | 9.1 | 0.2% | Sep 25, 2026 | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKC... |
| CVE-2026-92288 | CRITICAL | 9.1 | 0.2% | Sep 25, 2026 | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth... |
| CVE-2026-97230 | CRITICAL | 9.8 | 0.1% | Sep 24, 2026 | IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated U... |
| CVE-2026-95699 | CRITICAL | 9.6 | 0.3% | Sep 24, 2026 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT ... |
| CVE-2026-93291 | CRITICAL | 9.4 | — | Sep 24, 2026 | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which c... |
| CVE-2026-86860 | CRITICAL | 9.3 | — | Sep 24, 2026 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This ... |
| CVE-2026-13249 | CRITICAL | 9.8 | — | Sep 24, 2026 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Hone... |
| CVE-2026-13016 | CRITICAL | 9.3 | — | Sep 24, 2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerab... |
| CVE-2026-61742 | CRITICAL | 9.3 | — | Sep 24, 2026 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose... |
| CVE-2026-61741 | CRITICAL | 9.3 | — | Sep 24, 2026 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions ... |
| CVE-2026-61732 | CRITICAL | 10 | — | Sep 24, 2026 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of... |
| CVE-2026-61604 | CRITICAL | 9.3 | — | Sep 24, 2026 | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds mo... |
| CVE-2026-97413 | CRITICAL | 9.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_rea... |
| CVE-2026-79766 | CRITICAL | 9.1 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1... |
| CVE-2026-93425 | CRITICAL | 9.9 | — | Sep 24, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC proc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now