2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-20180CRITICAL9.9A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra...
CVE-2026-20170MEDIUM6.1A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, ...
CVE-2026-20161MEDIUM5.5A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low ...
CVE-2026-20152MEDIUM5.3A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all...
CVE-2026-20148MEDIUM4.9A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal a...
CVE-2026-20147CRITICAL9.9A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary comman...
CVE-2026-20136MEDIUM6A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI...
CVE-2026-20132MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au...
CVE-2026-20081MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20078MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20061MEDIUM6.5A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att...
CVE-2026-20060MEDIUM4.7A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-20059MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-5387CRITICAL9.3The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simula...
CVE-2026-30625CRITICAL9.8Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The applica...
CVE-2026-30624HIGH8.6Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The a...
CVE-2026-30617HIGH8.6LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execut...
CVE-2026-30616HIGH7.3Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacke...
CVE-2026-30615HIGH8A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim...
CVE-2026-30461HIGH8.3Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ...
CVE-2026-20205HIGH7.2In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or p...
CVE-2026-20204HIGH7.1In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-20203MEDIUM4.3In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-20202MEDIUM6.6In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-4682HIGH8.7Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specia...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now