2026 CVE Vulnerabilities
65,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20180 | CRITICAL | 9.9 | 6.0% | Apr 15, 2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra... |
| CVE-2026-20170 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, ... |
| CVE-2026-20161 | MEDIUM | 5.5 | 0.1% | Apr 15, 2026 | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low ... |
| CVE-2026-20152 | MEDIUM | 5.3 | 0.3% | Apr 15, 2026 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all... |
| CVE-2026-20148 | MEDIUM | 4.9 | 6.5% | Apr 15, 2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal a... |
| CVE-2026-20147 | CRITICAL | 9.9 | 10.4% | Apr 15, 2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary comman... |
| CVE-2026-20136 | MEDIUM | 6 | 0.5% | Apr 15, 2026 | A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI... |
| CVE-2026-20132 | MEDIUM | 4.8 | 0.2% | Apr 15, 2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au... |
| CVE-2026-20081 | MEDIUM | 6.5 | 0.4% | Apr 15, 2026 | Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr... |
| CVE-2026-20078 | MEDIUM | 6.5 | 0.4% | Apr 15, 2026 | Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr... |
| CVE-2026-20061 | MEDIUM | 6.5 | 0.2% | Apr 15, 2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att... |
| CVE-2026-20060 | MEDIUM | 4.7 | 0.2% | Apr 15, 2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a... |
| CVE-2026-20059 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a... |
| CVE-2026-5387 | CRITICAL | 9.3 | 0.4% | Apr 15, 2026 | The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simula... |
| CVE-2026-30625 | CRITICAL | 9.8 | 1.0% | Apr 15, 2026 | Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The applica... |
| CVE-2026-30624 | HIGH | 8.6 | 0.4% | Apr 15, 2026 | Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The a... |
| CVE-2026-30617 | HIGH | 8.6 | 0.5% | Apr 15, 2026 | LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execut... |
| CVE-2026-30616 | HIGH | 7.3 | 0.3% | Apr 15, 2026 | Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacke... |
| CVE-2026-30615 | HIGH | 8 | 0.3% | Apr 15, 2026 | A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim... |
| CVE-2026-30461 | HIGH | 8.3 | 0.6% | Apr 15, 2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ... |
| CVE-2026-20205 | HIGH | 7.2 | 0.3% | Apr 15, 2026 | In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or p... |
| CVE-2026-20204 | HIGH | 7.1 | 3.3% | Apr 15, 2026 | In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-20203 | MEDIUM | 4.3 | 0.2% | Apr 15, 2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-20202 | MEDIUM | 6.6 | 0.2% | Apr 15, 2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-4682 | HIGH | 8.7 | 0.3% | Apr 15, 2026 | Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specia... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now