2026 CVE Vulnerabilities
67,251 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63416 | LOW | 3.7 | 0.4% | Sep 21, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/... |
| CVE-2026-63373 | MEDIUM | 4.2 | 0.1% | Sep 21, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler... |
| CVE-2026-63334 | MEDIUM | 6.8 | 0.2% | Sep 21, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DR... |
| CVE-2026-63116 | HIGH | 8.8 | 0.5% | Sep 21, 2026 | deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From... |
| CVE-2026-62987 | MEDIUM | 5.8 | 0.2% | Sep 21, 2026 | Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48... |
| CVE-2026-62866 | MEDIUM | 6.2 | 0.2% | Sep 21, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
| CVE-2026-62371 | HIGH | 8.8 | 0.9% | Sep 21, 2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ... |
| CVE-2026-62370 | MEDIUM | 6.5 | 0.5% | Sep 21, 2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ... |
| CVE-2026-61674 | CRITICAL | 9.2 | 0.9% | Sep 21, 2026 | Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0... |
| CVE-2026-59168 | MEDIUM | 6.2 | 0.1% | Sep 21, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
| CVE-2026-58504 | MEDIUM | 6.1 | 0.4% | Sep 21, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a cra... |
| CVE-2026-17051 | MEDIUM | 6 | 0.1% | Sep 21, 2026 | The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ip... |
| CVE-2026-17050 | MEDIUM | 5.7 | 0.2% | Sep 21, 2026 | The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicat... |
| CVE-2026-88978 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, t... |
| CVE-2026-85751 | CRITICAL | 9.8 | 1.1% | Sep 21, 2026 | Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-ch... |
| CVE-2026-84298 | LOW | 3.1 | 0.2% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, th... |
| CVE-2026-82412 | HIGH | 8.8 | 0.4% | Sep 21, 2026 | ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scri... |
| CVE-2026-77166 | LOW | 2.4 | 0.2% | Sep 21, 2026 | The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line... |
| CVE-2026-77165 | MEDIUM | 6.5 | 0.3% | Sep 21, 2026 | File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recov... |
| CVE-2026-63342 | MEDIUM | 6.3 | 0.3% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ap... |
| CVE-2026-61687 | HIGH | 7.1 | 0.2% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, Va... |
| CVE-2026-61681 | MEDIUM | 4.1 | 0.3% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, th... |
| CVE-2026-55563 | HIGH | 8.9 | 0.5% | Sep 21, 2026 | Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_te... |
| CVE-2026-53940 | HIGH | 8.8 | 0.5% | Sep 21, 2026 | Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior... |
| CVE-2026-36472 | MEDIUM | 5.2 | 0.2% | Sep 21, 2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now