2026 CVE Vulnerabilities

66,483 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28728MEDIUM6.7Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (...
CVE-2026-27774MEDIUM6.7Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (...
CVE-2026-26962MEDIUM6.5Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds...
CVE-2026-5360LOW3.7A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such...
CVE-2026-5355HIGH8.8A vulnerability has been found in Trendnet TEW-657BRM 1.00.1. Affected by this issue is the function vpn_drop of the fil...
CVE-2026-5354HIGH8.8A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the f...
CVE-2026-5353HIGH8.8A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. P...
CVE-2026-5352HIGH8.8A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /se...
CVE-2026-35388LOW2.5OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-35387MEDIUM6.5OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or H...
CVE-2026-35386HIGH8.1In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This r...
CVE-2026-35385HIGH8.1In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' e...
CVE-2026-35038MEDIUM6.5Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbit...
CVE-2026-34877CRITICAL9.8An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of seriali...
CVE-2026-34831MEDIUM6.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Cont...
CVE-2026-34830HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path ...
CVE-2026-34829HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only w...
CVE-2026-34826HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges pa...
CVE-2026-34786MEDIUM5.3Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules ...
CVE-2026-34785HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whethe...
CVE-2026-34763MEDIUM5.3Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates t...
CVE-2026-34230HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encodi...
CVE-2026-34083MEDIUM6.1Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server co...
CVE-2026-33951HIGH7.5Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the Signal...
CVE-2026-33950CRITICAL9.4Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now