2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6330 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's i... |
| CVE-2026-6329 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and all... |
| CVE-2026-6092 | MEDIUM | 5.3 | 0.1% | Jun 25, 2026 | When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing E... |
| CVE-2026-55962 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the cl... |
| CVE-2026-44622 | MEDIUM | 6.9 | 0.2% | Jun 25, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-13282 | MEDIUM | 6.8 | 0.1% | Jun 25, 2026 | Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e... |
| CVE-2026-10098 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose se... |
| CVE-2026-6681 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written... |
| CVE-2026-6678 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handlin... |
| CVE-2026-6450 | MEDIUM | 5.3 | 0.1% | Jun 25, 2026 | A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allow... |
| CVE-2026-6412 | MEDIUM | 4.3 | 0.1% | Jun 25, 2026 | Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate proce... |
| CVE-2026-57522 | MEDIUM | 5 | 0.3% | Jun 25, 2026 | Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens()... |
| CVE-2026-57521 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to ac... |
| CVE-2026-55964 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to ha... |
| CVE-2026-2299 | MEDIUM | 4.3 | 0.1% | Jun 25, 2026 | The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoi... |
| CVE-2026-10592 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildca... |
| CVE-2026-56779 | MEDIUM | 6.4 | 0.2% | Jun 25, 2026 | MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allo... |
| CVE-2026-56774 | MEDIUM | 5.4 | 0.3% | Jun 25, 2026 | Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id par... |
| CVE-2026-56772 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private no... |
| CVE-2026-54250 | MEDIUM | 5.8 | 0.1% | Jun 25, 2026 | K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a ... |
| CVE-2026-54093 | MEDIUM | 6.8 | 0.2% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54092 | MEDIUM | 6.5 | 0.5% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-46611 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s,... |
| CVE-2026-28898 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing t... |
| CVE-2026-6291 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now