2026 CVE Vulnerabilities
67,452 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16514 | MEDIUM | 4.3 | — | Sep 18, 2026 | gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS ... |
| CVE-2026-16512 | LOW | 3.1 | — | Sep 18, 2026 | gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched... |
| CVE-2026-10832 | MEDIUM | 5.9 | — | Sep 18, 2026 | A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaus... |
| CVE-2026-93606 | CRITICAL | 10 | — | Sep 18, 2026 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API... |
| CVE-2026-93605 | CRITICAL | 10 | 0.4% | Sep 18, 2026 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chi... |
| CVE-2026-93604 | HIGH | 7.2 | — | Sep 18, 2026 | vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allow... |
| CVE-2026-93603 | CRITICAL | 10 | 0.4% | Sep 18, 2026 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge... |
| CVE-2026-93602 | MEDIUM | 4.4 | 0.2% | Sep 18, 2026 | rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares onl... |
| CVE-2026-93601 | LOW | 2.2 | 0.2% | Sep 18, 2026 | rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorr... |
| CVE-2026-93600 | LOW | 2.2 | 0.2% | Sep 18, 2026 | rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore... |
| CVE-2026-93599 | HIGH | 7.5 | 0.3% | Sep 18, 2026 | rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_str... |
| CVE-2026-93598 | HIGH | 7.1 | 0.5% | Sep 18, 2026 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot s... |
| CVE-2026-93597 | HIGH | 7.7 | — | Sep 18, 2026 | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and... |
| CVE-2026-93596 | MEDIUM | 4.3 | — | Sep 18, 2026 | ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the Datab... |
| CVE-2026-93595 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI... |
| CVE-2026-93594 | HIGH | 8.1 | — | Sep 18, 2026 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control ru... |
| CVE-2026-93593 | HIGH | 8.1 | 0.2% | Sep 18, 2026 | ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver b... |
| CVE-2026-93592 | HIGH | 7.5 | — | Sep 18, 2026 | vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, ... |
| CVE-2026-93591 | HIGH | 7.6 | — | Sep 18, 2026 | SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values... |
| CVE-2026-93590 | LOW | 3.7 | 0.3% | Sep 18, 2026 | ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy chec... |
| CVE-2026-93589 | LOW | 3.7 | 0.3% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for t... |
| CVE-2026-93588 | LOW | 3.1 | 0.3% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder re... |
| CVE-2026-93587 | LOW | 3.3 | 0.1% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CU... |
| CVE-2026-93586 | LOW | 2.9 | 0.1% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau... |
| CVE-2026-93560 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-l... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now