2026 CVE Vulnerabilities

45,571 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-27606CRITICAL9.8Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (sp...
CVE-2026-3135CRITICAL9.8A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of t...
CVE-2026-3134CRITICAL9.8A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function...
CVE-2026-3133CRITICAL9.8A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processin...
CVE-2026-22553CRITICAL9.8All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web in...
CVE-2026-21410CRITICAL9.8InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vu...
CVE-2026-26342CRITICAL9.8Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X...
CVE-2026-26341CRITICAL9.8Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that a...
CVE-2026-26222CRITICAL9.8Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP...
CVE-2026-27590CRITICAL9.8Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting...
CVE-2026-27588CRITICAL9.1Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request ma...
CVE-2026-27587CRITICAL9.1Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request ma...
CVE-2026-27586CRITICAL9.1Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `Clien...
CVE-2026-27515CRITICAL9.3Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session ide...
CVE-2026-27507CRITICAL9.8Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative creden...
CVE-2026-2807CRITICAL9.8Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption a...
CVE-2026-2806CRITICAL9.1Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
CVE-2026-2805CRITICAL9.8Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
CVE-2026-2800CRITICAL9.8Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunder...
CVE-2026-2799CRITICAL9.8Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
CVE-2026-2797CRITICAL9.8Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
CVE-2026-2796CRITICAL9.8JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird...
CVE-2026-2795CRITICAL9.8Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
CVE-2026-2793CRITICAL9.8Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird ...
CVE-2026-2792CRITICAL9.8Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these b...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now