2026 CVE Vulnerabilities
67,445 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1037 | MEDIUM | 6.1 | — | Sep 18, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro... |
| CVE-2026-1031 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro... |
| CVE-2026-1030 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error m... |
| CVE-2026-1029 | MEDIUM | 5.4 | — | Sep 18, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro... |
| CVE-2026-1025 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro... |
| CVE-2026-11537 | MEDIUM | 4.3 | 0.2% | Sep 18, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the fi... |
| CVE-2026-11381 | HIGH | 8.8 | — | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to i... |
| CVE-2026-11378 | HIGH | 8.8 | 0.6% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a... |
| CVE-2026-11375 | HIGH | 8.8 | 0.6% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a... |
| CVE-2026-10858 | CRITICAL | 9.9 | — | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote... |
| CVE-2026-10853 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arb... |
| CVE-2026-10841 | MEDIUM | 4.8 | 0.2% | Sep 18, 2026 | IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling. |
| CVE-2026-10751 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applicati... |
| CVE-2026-10747 | CRITICAL | 10 | 0.5% | Sep 18, 2026 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to... |
| CVE-2026-10744 | HIGH | 7.5 | — | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote... |
| CVE-2026-10575 | HIGH | 8.8 | 0.5% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a he... |
| CVE-2026-10030 | HIGH | 7.1 | — | Sep 18, 2026 | IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authoriz... |
| CVE-2026-10027 | CRITICAL | 9.8 | 0.4% | Sep 18, 2026 | IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow whe... |
| CVE-2026-93685 | MEDIUM | 5.4 | 0.4% | Sep 18, 2026 | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authenti... |
| CVE-2026-93676 | LOW | 3.2 | 0.1% | Sep 18, 2026 | xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictio... |
| CVE-2026-93660 | MEDIUM | 6.5 | 0.2% | Sep 18, 2026 | SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authe... |
| CVE-2026-93659 | HIGH | 8.1 | — | Sep 18, 2026 | Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a... |
| CVE-2026-93658 | HIGH | 7 | 0.2% | Sep 18, 2026 | uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership ... |
| CVE-2026-93657 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and R... |
| CVE-2026-93653 | MEDIUM | 5.5 | — | Sep 18, 2026 | A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now