2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0209MEDIUM6.9Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than c...
CVE-2026-0207HIGH8.5A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.
CVE-2026-34626MEDIUM6.3Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo...
CVE-2026-34622HIGH8.6Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo...
CVE-2026-27291HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-27286MEDIUM5.5InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-27285MEDIUM5.5InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-27284HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cr...
CVE-2026-27283HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in a...
CVE-2026-27238HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-22692MEDIUM6.8October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4...
CVE-2026-5713MEDIUM5.3The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" a...
CVE-2026-4832MEDIUM6.9CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device info...
CVE-2026-39815HIGH8.8A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDD...
CVE-2026-39814MEDIUM6.7A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb...
CVE-2026-39813CRITICAL9.8A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4....
CVE-2026-39812MEDIUM4.8A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa...
CVE-2026-39811MEDIUM4.9A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, F...
CVE-2026-39810MEDIUM5.5A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to...
CVE-2026-39809MEDIUM6.7A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCl...
CVE-2026-39808CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2026-38533MEDIUM6.5An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attac...
CVE-2026-38532HIGH8.1A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2...
CVE-2026-38530HIGH8.1A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2....
CVE-2026-38529HIGH8.8A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now