2026 CVE Vulnerabilities
67,265 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-75939 | HIGH | 7.4 | 0.2% | Sep 21, 2026 | A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signature... |
| CVE-2026-75158 | MEDIUM | 4.3 | 0.4% | Sep 21, 2026 | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting ... |
| CVE-2026-71543 | HIGH | 7.5 | 0.4% | Sep 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies... |
| CVE-2026-68919 | HIGH | 7 | 0.5% | Sep 21, 2026 | GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious mater... |
| CVE-2026-61630 | MEDIUM | 4.2 | 0.4% | Sep 21, 2026 | nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enable... |
| CVE-2026-61629 | HIGH | 7.5 | 0.6% | Sep 21, 2026 | nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware ... |
| CVE-2026-61628 | HIGH | 8.1 | 0.4% | Sep 21, 2026 | nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish... |
| CVE-2026-55870 | LOW | 2.3 | 0.4% | Sep 21, 2026 | GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in... |
| CVE-2026-55625 | MEDIUM | 4.9 | 0.5% | Sep 21, 2026 | GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/adm... |
| CVE-2026-55567 | HIGH | 7.8 | 0.1% | Sep 21, 2026 | BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not ... |
| CVE-2026-55074 | HIGH | 8.2 | 0.4% | Sep 21, 2026 | Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.... |
| CVE-2026-55071 | HIGH | 8.4 | 0.3% | Sep 21, 2026 | MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0... |
| CVE-2026-55060 | LOW | 3.7 | 0.3% | Sep 21, 2026 | GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforc... |
| CVE-2026-54584 | MEDIUM | 5.3 | 0.5% | Sep 21, 2026 | mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including w... |
| CVE-2026-52743 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a ... |
| CVE-2026-52742 | MEDIUM | 5.1 | 0.5% | Sep 21, 2026 | GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical... |
| CVE-2026-52741 | HIGH | 7.5 | 0.4% | Sep 21, 2026 | GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from comm... |
| CVE-2026-52740 | MEDIUM | 5.3 | 0.4% | Sep 21, 2026 | GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names ca... |
| CVE-2026-94404 | HIGH | 7.1 | — | Sep 21, 2026 | MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser ... |
| CVE-2026-94401 | HIGH | 8.3 | — | Sep 21, 2026 | MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access i... |
| CVE-2026-94394 | MEDIUM | 6.3 | — | Sep 21, 2026 | When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall ... |
| CVE-2026-94393 | MEDIUM | 6.4 | — | Sep 21, 2026 | When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without prope... |
| CVE-2026-94387 | MEDIUM | 5.4 | — | Sep 21, 2026 | Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_v... |
| CVE-2026-94382 | MEDIUM | 4.2 | 0.2% | Sep 21, 2026 | Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-... |
| CVE-2026-93884 | — | — | — | Sep 21, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now