2026 CVE Vulnerabilities

68,816 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2491MEDIUM6.3Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to...
CVE-2026-2476MEDIUM4.3Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with...
CVE-2026-2463MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user perm...
CVE-2026-2462MEDIUM6.6Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI t...
CVE-2026-2461MEDIUM4.3Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modi...
CVE-2026-2458MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership wh...
CVE-2026-2457MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metada...
CVE-2026-2456MEDIUM5.7Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of respon...
CVE-2026-2326——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-2233MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-28522HIGH7.1arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An att...
CVE-2026-28521HIGH7.7arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An a...
CVE-2026-28520HIGH8.6arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. W...
CVE-2026-28519HIGH8.8arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An...
CVE-2026-26246MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process...
CVE-2026-26133HIGH7.1AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-25783MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header ...
CVE-2026-25780MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process...
CVE-2026-25083HIGH8.7GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logg...
CVE-2026-24458HIGH7.5Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords,...
CVE-2026-21005MEDIUM6.5Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Sm...
CVE-2026-21004MEDIUM6.5Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of serv...
CVE-2026-21002MEDIUM5.5Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to inst...
CVE-2026-21001MEDIUM5.5Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privileg...
CVE-2026-21000MEDIUM5.5Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now