2026 CVE Vulnerabilities
67,353 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57224 | MEDIUM | 6.5 | — | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr... |
| CVE-2026-57222 | MEDIUM | 5.3 | — | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-52745 | MEDIUM | 5.3 | 0.3% | Sep 18, 2026 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior t... |
| CVE-2026-18869 | MEDIUM | 6.4 | 0.2% | Sep 18, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access inte... |
| CVE-2026-17619 | HIGH | 8.6 | 0.3% | Sep 18, 2026 | IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which co... |
| CVE-2026-17262 | MEDIUM | 5.4 | 0.2% | Sep 18, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP... |
| CVE-2026-11727 | HIGH | 8.1 | 0.6% | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service... |
| CVE-2026-11726 | HIGH | 8.1 | 0.5% | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or c... |
| CVE-2026-11725 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a... |
| CVE-2026-11722 | MEDIUM | 4.8 | 0.2% | Sep 18, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vuln... |
| CVE-2026-11716 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote... |
| CVE-2026-11711 | MEDIUM | 6.5 | 0.4% | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service componen... |
| CVE-2026-11710 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of ... |
| CVE-2026-11549 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerab... |
| CVE-2026-11548 | MEDIUM | 4.8 | 0.2% | Sep 18, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vuln... |
| CVE-2026-11545 | LOW | 3.7 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the admi... |
| CVE-2026-11540 | MEDIUM | 5.3 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the fil... |
| CVE-2026-11539 | MEDIUM | 5.3 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX conne... |
| CVE-2026-93854 | HIGH | 7.2 | 0.2% | Sep 18, 2026 | In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete... |
| CVE-2026-93852 | HIGH | 7.1 | 0.2% | Sep 18, 2026 | In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project with... |
| CVE-2026-93650 | LOW | 3.7 | — | Sep 18, 2026 | A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function... |
| CVE-2026-75894 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrar... |
| CVE-2026-75893 | HIGH | 7.5 | 0.1% | Sep 18, 2026 | In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg() fun... |
| CVE-2026-75892 | MEDIUM | 6.5 | 0.1% | Sep 18, 2026 | In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context ... |
| CVE-2026-11538 | MEDIUM | 5.3 | 0.2% | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token coo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now