2026 CVE Vulnerabilities

67,228 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4707HIGH7.5Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ...
CVE-2026-4706HIGH7.5Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ...
CVE-2026-4705CRITICAL9.8Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, T...
CVE-2026-4704HIGH7.5Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Th...
CVE-2026-4702CRITICAL9.8JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, T...
CVE-2026-4701CRITICAL9.8Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thund...
CVE-2026-4700CRITICAL9.8Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thu...
CVE-2026-4699HIGH7.5Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Fire...
CVE-2026-4698CRITICAL9.8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115...
CVE-2026-4697HIGH7.5Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Fir...
CVE-2026-4696CRITICAL9.8Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34,...
CVE-2026-4695HIGH7.5Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Fir...
CVE-2026-4694HIGH7.5Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, ...
CVE-2026-4693HIGH7.5Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firef...
CVE-2026-4692CRITICAL10Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34,...
CVE-2026-4691CRITICAL9.8Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 11...
CVE-2026-4690HIGH8.6Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fix...
CVE-2026-4689CRITICAL10Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fix...
CVE-2026-4688CRITICAL10Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 14...
CVE-2026-4687HIGH8.6Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability was fixed in Firefox ...
CVE-2026-4686HIGH7.5Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ...
CVE-2026-4685HIGH7.5Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ...
CVE-2026-4684HIGH7.5Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox 149, Firefo...
CVE-2026-33475CRITICAL9.1Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection...
CVE-2026-33309CRITICAL9.9Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypas...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now