2026 CVE Vulnerabilities
68,816 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2491 | MEDIUM | 6.3 | 0.4% | Mar 16, 2026 | Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to... |
| CVE-2026-2476 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with... |
| CVE-2026-2463 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user perm... |
| CVE-2026-2462 | MEDIUM | 6.6 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI t... |
| CVE-2026-2461 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modi... |
| CVE-2026-2458 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership wh... |
| CVE-2026-2457 | MEDIUM | 4.3 | 0.1% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metada... |
| CVE-2026-2456 | MEDIUM | 5.7 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of respon... |
| CVE-2026-2326 | — | — | — | Mar 16, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-2233 | MEDIUM | 5.3 | 0.2% | Mar 16, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-28522 | HIGH | 7.1 | 0.3% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An att... |
| CVE-2026-28521 | HIGH | 7.7 | 0.2% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An a... |
| CVE-2026-28520 | HIGH | 8.6 | 0.2% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. W... |
| CVE-2026-28519 | HIGH | 8.8 | 0.4% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An... |
| CVE-2026-26246 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process... |
| CVE-2026-26133 | HIGH | 7.1 | 0.4% | Mar 16, 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-25783 | MEDIUM | 4.3 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header ... |
| CVE-2026-25780 | MEDIUM | 4.3 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process... |
| CVE-2026-25083 | HIGH | 8.7 | 0.3% | Mar 16, 2026 | GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logg... |
| CVE-2026-24458 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords,... |
| CVE-2026-21005 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Sm... |
| CVE-2026-21004 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of serv... |
| CVE-2026-21002 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to inst... |
| CVE-2026-21001 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privileg... |
| CVE-2026-21000 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now