2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-15969CRITICAL9.8SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl...
CVE-2026-13435CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox impl...
CVE-2026-12943CRITICAL9.8IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power en...
CVE-2026-12118CRITICAL9.8IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary co...
CVE-2026-13379CRITICAL9.1The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS stat...
CVE-2026-12940CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable ...
CVE-2026-52680CRITICAL9.8Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary...
CVE-2026-4978CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffi...
CVE-2026-28812CRITICAL9.8UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate pri...
CVE-2026-28323CRITICAL9.8SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2...
CVE-2026-53431CRITICAL9.1Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previous...
CVE-2026-15435CRITICAL9.8IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to t...
CVE-2026-14522CRITICAL9.8IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to e...
CVE-2026-11707CRITICAL9.3IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site sc...
CVE-2026-59310CRITICAL9.8VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access ...
CVE-2026-59309CRITICAL9.8VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with n...
CVE-2026-54363CRITICAL9.3CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to fo...
CVE-2026-47876CRITICAL9.3VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with ...
CVE-2026-17544CRITICAL9.8Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions...
CVE-2026-17543CRITICAL9.8Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f...
CVE-2026-18363CRITICAL9.1A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17....
CVE-2026-7849CRITICAL9.8Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into ...
CVE-2026-44108CRITICAL9.8Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system sh...
CVE-2026-44104CRITICAL9.8The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryp...
CVE-2026-44101CRITICAL9.8Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now