2026 CVE Vulnerabilities

67,452 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16514MEDIUM4.3gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS ...
CVE-2026-16512LOW3.1gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched...
CVE-2026-10832MEDIUM5.9A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaus...
CVE-2026-93606CRITICAL10vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API...
CVE-2026-93605CRITICAL10vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chi...
CVE-2026-93604HIGH7.2vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allow...
CVE-2026-93603CRITICAL10vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge...
CVE-2026-93602MEDIUM4.4rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares onl...
CVE-2026-93601LOW2.2rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorr...
CVE-2026-93600LOW2.2rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore...
CVE-2026-93599HIGH7.5rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_str...
CVE-2026-93598HIGH7.1ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot s...
CVE-2026-93597HIGH7.7ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and...
CVE-2026-93596MEDIUM4.3ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the Datab...
CVE-2026-93595MEDIUM6.5ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI...
CVE-2026-93594HIGH8.1ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control ru...
CVE-2026-93593HIGH8.1ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver b...
CVE-2026-93592HIGH7.5vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, ...
CVE-2026-93591HIGH7.6SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values...
CVE-2026-93590LOW3.7ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy chec...
CVE-2026-93589LOW3.7ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for t...
CVE-2026-93588LOW3.1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder re...
CVE-2026-93587LOW3.3ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CU...
CVE-2026-93586LOW2.9ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau...
CVE-2026-93560HIGH7.5A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-l...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now