2026 CVE Vulnerabilities

68,670 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27166MEDIUM5.4Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficie...
CVE-2026-26139HIGH8.6Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-26138CRITICAL10Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-26137CRITICAL9.9Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a netw...
CVE-2026-26136HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-26120HIGH7.5Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network...
CVE-2026-24299MEDIUM5.3Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-23659HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disc...
CVE-2026-23658CRITICAL9.8Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a networ...
CVE-2026-3580MEDIUM4.7In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by...
CVE-2026-3579MEDIUM5.9wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The...
CVE-2026-32238CRITICAL9.1OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2026-32119MEDIUM4.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-25928MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-25744MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-3503MEDIUM5.2Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi...
CVE-2026-25667HIGH7.5ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause ex...
CVE-2026-3548CRITICAL9.8Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer over...
CVE-2026-30694CRITICAL9.8An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter compone...
CVE-2026-2646HIGH8.1A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session ...
CVE-2026-2645HIGH7.5In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could ...
CVE-2026-26940MEDIUM6.5Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead De...
CVE-2026-26939MEDIUM6.5Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Resp...
CVE-2026-26933MEDIUM5.7Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser...
CVE-2026-30403HIGH7.5There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now