2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15969 | CRITICAL | 9.8 | 1.0% | Jul 30, 2026 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl... |
| CVE-2026-13435 | CRITICAL | 9.9 | 0.3% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox impl... |
| CVE-2026-12943 | CRITICAL | 9.8 | 0.9% | Jul 30, 2026 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power en... |
| CVE-2026-12118 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary co... |
| CVE-2026-13379 | CRITICAL | 9.1 | 0.3% | Jul 30, 2026 | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS stat... |
| CVE-2026-12940 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable ... |
| CVE-2026-52680 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary... |
| CVE-2026-4978 | CRITICAL | 9.8 | — | Jul 30, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffi... |
| CVE-2026-28812 | CRITICAL | 9.8 | 0.3% | Jul 30, 2026 | UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate pri... |
| CVE-2026-28323 | CRITICAL | 9.8 | — | Jul 30, 2026 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2... |
| CVE-2026-53431 | CRITICAL | 9.1 | — | Jul 30, 2026 | Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previous... |
| CVE-2026-15435 | CRITICAL | 9.8 | 0.7% | Jul 30, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to t... |
| CVE-2026-14522 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to e... |
| CVE-2026-11707 | CRITICAL | 9.3 | — | Jul 30, 2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site sc... |
| CVE-2026-59310 | CRITICAL | 9.8 | — | Jul 30, 2026 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access ... |
| CVE-2026-59309 | CRITICAL | 9.8 | — | Jul 30, 2026 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with n... |
| CVE-2026-54363 | CRITICAL | 9.3 | — | Jul 30, 2026 | CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to fo... |
| CVE-2026-47876 | CRITICAL | 9.3 | — | Jul 30, 2026 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with ... |
| CVE-2026-17544 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions... |
| CVE-2026-17543 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f... |
| CVE-2026-18363 | CRITICAL | 9.1 | — | Jul 30, 2026 | A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.... |
| CVE-2026-7849 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into ... |
| CVE-2026-44108 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system sh... |
| CVE-2026-44104 | CRITICAL | 9.8 | 0.2% | Jul 30, 2026 | The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryp... |
| CVE-2026-44101 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now