2026 CVE Vulnerabilities
45,571 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27606 | CRITICAL | 9.8 | 1.4% | Feb 25, 2026 | Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (sp... |
| CVE-2026-3135 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of t... |
| CVE-2026-3134 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function... |
| CVE-2026-3133 | CRITICAL | 9.8 | 0.4% | Feb 25, 2026 | A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processin... |
| CVE-2026-22553 | CRITICAL | 9.8 | 1.4% | Feb 24, 2026 | All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web in... |
| CVE-2026-21410 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vu... |
| CVE-2026-26342 | CRITICAL | 9.8 | 0.7% | Feb 24, 2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X... |
| CVE-2026-26341 | CRITICAL | 9.8 | 2.7% | Feb 24, 2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that a... |
| CVE-2026-26222 | CRITICAL | 9.8 | 0.7% | Feb 24, 2026 | Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP... |
| CVE-2026-27590 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting... |
| CVE-2026-27588 | CRITICAL | 9.1 | 0.4% | Feb 24, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request ma... |
| CVE-2026-27587 | CRITICAL | 9.1 | 0.4% | Feb 24, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request ma... |
| CVE-2026-27586 | CRITICAL | 9.1 | 0.3% | Feb 24, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `Clien... |
| CVE-2026-27515 | CRITICAL | 9.3 | 0.3% | Feb 24, 2026 | Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session ide... |
| CVE-2026-27507 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative creden... |
| CVE-2026-2807 | CRITICAL | 9.8 | 0.2% | Feb 24, 2026 | Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption a... |
| CVE-2026-2806 | CRITICAL | 9.1 | 0.4% | Feb 24, 2026 | Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
| CVE-2026-2805 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
| CVE-2026-2800 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunder... |
| CVE-2026-2799 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
| CVE-2026-2797 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
| CVE-2026-2796 | CRITICAL | 9.8 | 0.6% | Feb 24, 2026 | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird... |
| CVE-2026-2795 | CRITICAL | 9.8 | 0.2% | Feb 24, 2026 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
| CVE-2026-2793 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird ... |
| CVE-2026-2792 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these b... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now