2026 CVE Vulnerabilities
66,483 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28728 | MEDIUM | 6.7 | 0.1% | Apr 2, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (... |
| CVE-2026-27774 | MEDIUM | 6.7 | 0.1% | Apr 2, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (... |
| CVE-2026-26962 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds... |
| CVE-2026-5360 | LOW | 3.7 | 0.4% | Apr 2, 2026 | A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such... |
| CVE-2026-5355 | HIGH | 8.8 | 4.8% | Apr 2, 2026 | A vulnerability has been found in Trendnet TEW-657BRM 1.00.1. Affected by this issue is the function vpn_drop of the fil... |
| CVE-2026-5354 | HIGH | 8.8 | 4.8% | Apr 2, 2026 | A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the f... |
| CVE-2026-5353 | HIGH | 8.8 | 4.8% | Apr 2, 2026 | A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. P... |
| CVE-2026-5352 | HIGH | 8.8 | 4.1% | Apr 2, 2026 | A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /se... |
| CVE-2026-35388 | LOW | 2.5 | 0.1% | Apr 2, 2026 | OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions. |
| CVE-2026-35387 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or H... |
| CVE-2026-35386 | HIGH | 8.1 | 0.3% | Apr 2, 2026 | In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This r... |
| CVE-2026-35385 | HIGH | 8.1 | 0.6% | Apr 2, 2026 | In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' e... |
| CVE-2026-35038 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbit... |
| CVE-2026-34877 | CRITICAL | 9.8 | 0.4% | Apr 2, 2026 | An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of seriali... |
| CVE-2026-34831 | MEDIUM | 6.5 | 0.1% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Cont... |
| CVE-2026-34830 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path ... |
| CVE-2026-34829 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only w... |
| CVE-2026-34826 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges pa... |
| CVE-2026-34786 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules ... |
| CVE-2026-34785 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whethe... |
| CVE-2026-34763 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates t... |
| CVE-2026-34230 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encodi... |
| CVE-2026-34083 | MEDIUM | 6.1 | 0.1% | Apr 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server co... |
| CVE-2026-33951 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the Signal... |
| CVE-2026-33950 | CRITICAL | 9.4 | 0.4% | Apr 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now