2026 CVE Vulnerabilities

67,251 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63416LOW3.7draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/...
CVE-2026-63373MEDIUM4.2draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler...
CVE-2026-63334MEDIUM6.8draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DR...
CVE-2026-63116HIGH8.8deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From...
CVE-2026-62987MEDIUM5.8Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48...
CVE-2026-62866MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...
CVE-2026-62371HIGH8.8KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2026-62370MEDIUM6.5KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2026-61674CRITICAL9.2Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0...
CVE-2026-59168MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...
CVE-2026-58504MEDIUM6.1draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a cra...
CVE-2026-17051MEDIUM6The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ip...
CVE-2026-17050MEDIUM5.7The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicat...
CVE-2026-88978MEDIUM4.3Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, t...
CVE-2026-85751CRITICAL9.8Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-ch...
CVE-2026-84298LOW3.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, th...
CVE-2026-82412HIGH8.8ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scri...
CVE-2026-77166LOW2.4The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line...
CVE-2026-77165MEDIUM6.5File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recov...
CVE-2026-63342MEDIUM6.3Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ap...
CVE-2026-61687HIGH7.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, Va...
CVE-2026-61681MEDIUM4.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, th...
CVE-2026-55563HIGH8.9Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_te...
CVE-2026-53940HIGH8.8Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior...
CVE-2026-36472MEDIUM5.2CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now