2026 CVE Vulnerabilities
67,265 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17051 | MEDIUM | 6 | 0.1% | Sep 21, 2026 | The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ip... |
| CVE-2026-17050 | MEDIUM | 5.7 | 0.2% | Sep 21, 2026 | The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicat... |
| CVE-2026-88978 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, t... |
| CVE-2026-85751 | CRITICAL | 9.8 | 1.1% | Sep 21, 2026 | Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-ch... |
| CVE-2026-84298 | LOW | 3.1 | 0.2% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, th... |
| CVE-2026-82412 | HIGH | 8.8 | 0.4% | Sep 21, 2026 | ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scri... |
| CVE-2026-77166 | LOW | 2.4 | 0.2% | Sep 21, 2026 | The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line... |
| CVE-2026-77165 | MEDIUM | 6.5 | 0.3% | Sep 21, 2026 | File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recov... |
| CVE-2026-63342 | MEDIUM | 6.3 | 0.3% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ap... |
| CVE-2026-61687 | HIGH | 7.1 | 0.2% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, Va... |
| CVE-2026-61681 | MEDIUM | 4.1 | 0.3% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, th... |
| CVE-2026-55563 | HIGH | 8.9 | 0.5% | Sep 21, 2026 | Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_te... |
| CVE-2026-53940 | HIGH | 8.8 | 0.5% | Sep 21, 2026 | Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior... |
| CVE-2026-36472 | MEDIUM | 5.2 | 0.2% | Sep 21, 2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allow... |
| CVE-2026-36471 | MEDIUM | 5.8 | 0.3% | Sep 21, 2026 | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote att... |
| CVE-2026-36470 | MEDIUM | 5.8 | 0.1% | Sep 21, 2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied i... |
| CVE-2026-36469 | CRITICAL | 9.1 | 0.2% | Sep 21, 2026 | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Medi... |
| CVE-2026-36468 | MEDIUM | 6.1 | 0.2% | Sep 21, 2026 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitra... |
| CVE-2026-36467 | HIGH | 7.2 | 0.5% | Sep 21, 2026 | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticate... |
| CVE-2026-94301 | CRITICAL | 9.8 | — | Sep 21, 2026 | The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.ref... |
| CVE-2026-94184 | MEDIUM | 5.3 | 0.8% | Sep 21, 2026 | A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail ... |
| CVE-2026-93339 | MEDIUM | 5.4 | 0.3% | Sep 21, 2026 | Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that all... |
| CVE-2026-86473 | CRITICAL | 9.1 | 0.5% | Sep 21, 2026 | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client ... |
| CVE-2026-82355 | MEDIUM | 4.2 | 0.3% | Sep 21, 2026 | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airf... |
| CVE-2026-80110 | HIGH | 8.1 | 0.2% | Sep 21, 2026 | A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcar... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now