2026 CVE Vulnerabilities

67,770 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25534CRITICAL9.1### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddri...
CVE-2026-21570HIGH8.8This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, ...
CVE-2026-4148HIGH8.8A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu...
CVE-2026-4147MEDIUM4.3An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is...
CVE-2026-28506MEDIUM4.3Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for...
CVE-2026-24901HIGH8.8Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (I...
CVE-2026-23759HIGH8.6Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection ...
CVE-2026-21886HIGH8.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2026-4318HIGH8.8A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform...
CVE-2026-3564CRITICAL9A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material ...
CVE-2026-4324MEDIUM5.4A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of use...
CVE-2026-3888HIGH7.8Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private ...
CVE-2026-4271HIGH7.5A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs...
CVE-2026-30911HIGH8.1Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop...
CVE-2026-28779HIGH7.5Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configu...
CVE-2026-28563MEDIUM4.3Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filt...
CVE-2026-26929MEDIUM6.5Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filterin...
CVE-2026-3634MEDIUM6.5A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage...
CVE-2026-3633MEDIUM6.5A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function...
CVE-2026-3632MEDIUM5.5A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because ...
CVE-2026-23241MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at"...
CVE-2026-4208HIGH8.8The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible M...
CVE-2026-4202MEDIUM4.3The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of ...
CVE-2026-32586MEDIUM5.3Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectl...
CVE-2026-1323HIGH8.8The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now