2026 CVE Vulnerabilities
45,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13902 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker ... |
| CVE-2026-13900 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had com... |
| CVE-2026-13896 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navi... |
| CVE-2026-13895 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Autofill in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced... |
| CVE-2026-13894 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged n... |
| CVE-2026-13893 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Insufficient validation of untrusted input in WebUI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to... |
| CVE-2026-13892 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker ... |
| CVE-2026-13890 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised t... |
| CVE-2026-13889 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote at... |
| CVE-2026-13887 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had... |
| CVE-2026-13886 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker t... |
| CVE-2026-13881 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypa... |
| CVE-2026-13879 | MEDIUM | 6.5 | 0.1% | Jun 30, 2026 | Use after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to ... |
| CVE-2026-13877 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh... |
| CVE-2026-13876 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged netw... |
| CVE-2026-13875 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote at... |
| CVE-2026-13874 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive i... |
| CVE-2026-13873 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sen... |
| CVE-2026-13871 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Insufficient policy enforcement in GuestView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had c... |
| CVE-2026-13868 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Network in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who... |
| CVE-2026-13867 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform... |
| CVE-2026-13866 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who h... |
| CVE-2026-13865 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attack... |
| CVE-2026-13862 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.... |
| CVE-2026-13860 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Incorrect security UI in Autofill in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now