2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66779 | MEDIUM | 6.3 | 0.2% | Aug 11, 2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker co... |
| CVE-2026-66778 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A... |
| CVE-2026-66777 | MEDIUM | 5.9 | 0.3% | Aug 11, 2026 | SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D... |
| CVE-2026-66776 | MEDIUM | 5.9 | 0.1% | Aug 11, 2026 | SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec... |
| CVE-2026-66775 | MEDIUM | 4.3 | 0.1% | Aug 11, 2026 | SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent... |
| CVE-2026-66773 | MEDIUM | 5.9 | 0.2% | Aug 11, 2026 | A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i... |
| CVE-2026-66772 | MEDIUM | 4.3 | 0.2% | Aug 11, 2026 | SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer... |
| CVE-2026-66771 | MEDIUM | 6.1 | 0.2% | Aug 11, 2026 | SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted applicatio... |
| CVE-2026-66770 | MEDIUM | 6.3 | 0.2% | Aug 11, 2026 | Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL... |
| CVE-2026-66764 | MEDIUM | 4.3 | 0.2% | Aug 11, 2026 | Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user... |
| CVE-2026-66761 | MEDIUM | 4.3 | 0.2% | Aug 11, 2026 | SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s... |
| CVE-2026-66760 | MEDIUM | 6.4 | 0.1% | Aug 11, 2026 | SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges... |
| CVE-2026-58248 | MEDIUM | 6.5 | 0.3% | Aug 11, 2026 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci... |
| CVE-2026-58247 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul... |
| CVE-2026-58244 | MEDIUM | 4.3 | 0.2% | Aug 11, 2026 | SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati... |
| CVE-2026-58241 | MEDIUM | 4.2 | 0.2% | Aug 11, 2026 | SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privi... |
| CVE-2026-58238 | MEDIUM | 5.9 | 0.3% | Aug 11, 2026 | SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could... |
| CVE-2026-58237 | MEDIUM | 5.9 | 0.2% | Aug 11, 2026 | WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l... |
| CVE-2026-58236 | MEDIUM | 5.5 | 0.4% | Aug 11, 2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing securit... |
| CVE-2026-58235 | MEDIUM | 6.3 | 0.2% | Aug 11, 2026 | SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer... |
| CVE-2026-40130 | MEDIUM | 5.3 | 0.4% | Aug 11, 2026 | SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta... |
| CVE-2026-72919 | MEDIUM | 4.3 | 0.2% | Aug 10, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7... |
| CVE-2026-72918 | MEDIUM | 5.4 | 0.2% | Aug 10, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7... |
| CVE-2026-72917 | MEDIUM | 5.9 | — | Aug 10, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-72916 | MEDIUM | 6.3 | — | Aug 10, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now