2026 CVE Vulnerabilities
67,269 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87858 | HIGH | 7.2 | 0.4% | Sep 21, 2026 | Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An... |
| CVE-2026-65654 | HIGH | 8.7 | 0.6% | Sep 21, 2026 | github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's la... |
| CVE-2026-65653 | HIGH | 8.7 | 0.7% | Sep 21, 2026 | github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-pref... |
| CVE-2026-65652 | HIGH | 8.7 | 0.5% | Sep 21, 2026 | github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A n... |
| CVE-2026-65651 | HIGH | 8.7 | 0.6% | Sep 21, 2026 | temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstra... |
| CVE-2026-16652 | HIGH | 7.1 | 0.3% | Sep 21, 2026 | Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated cal... |
| CVE-2026-16651 | HIGH | 8.7 | 0.4% | Sep 21, 2026 | temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents... |
| CVE-2026-92612 | LOW | 1 | — | Sep 21, 2026 | In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe AP... |
| CVE-2026-77021 | MEDIUM | 5.3 | — | Sep 21, 2026 | Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (E... |
| CVE-2026-94277 | MEDIUM | 6.3 | — | Sep 21, 2026 | MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into ... |
| CVE-2026-92574 | HIGH | 8.8 | 0.7% | Sep 21, 2026 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container t... |
| CVE-2026-91921 | MEDIUM | 5.1 | 0.4% | Sep 21, 2026 | Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the... |
| CVE-2026-94152 | MEDIUM | 4.3 | 0.2% | Sep 21, 2026 | A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown fun... |
| CVE-2026-94151 | MEDIUM | 5.3 | 0.4% | Sep 21, 2026 | A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /ro... |
| CVE-2026-94150 | LOW | 2.4 | 0.2% | Sep 21, 2026 | A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function... |
| CVE-2026-92400 | MEDIUM | 5.3 | 0.1% | Sep 21, 2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment not... |
| CVE-2026-86802 | LOW | 3.7 | 0.2% | Sep 21, 2026 | The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and... |
| CVE-2026-85113 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before renderi... |
| CVE-2026-85010 | MEDIUM | 5.3 | 0.2% | Sep 21, 2026 | The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side w... |
| CVE-2026-15801 | HIGH | 8 | 0.3% | Sep 21, 2026 | A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to ... |
| CVE-2026-94149 | MEDIUM | 4.3 | — | Sep 21, 2026 | A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of t... |
| CVE-2026-94148 | MEDIUM | 5.3 | 0.3% | Sep 21, 2026 | A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /Sc... |
| CVE-2026-47321 | HIGH | 7.5 | 0.3% | Sep 21, 2026 | The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the ... |
| CVE-2026-94218 | LOW | 3.1 | 0.2% | Sep 21, 2026 | A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The i... |
| CVE-2026-94217 | LOW | 3.5 | 0.1% | Sep 21, 2026 | A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization toke... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now