2026 CVE Vulnerabilities

69,057 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-21672HIGH8.8A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.
CVE-2026-4044LOW3.8A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans....
CVE-2026-4043HIGH8.8A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDg...
CVE-2026-4042HIGH8.8A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of ...
CVE-2026-4041HIGH8.8A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/...
CVE-2026-28384CRITICAL9.9An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged u...
CVE-2026-21671CRITICAL9.1A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE)...
CVE-2026-21670MEDIUM6.5A vulnerability allowing a low-privileged user to extract saved SSH credentials.
CVE-2026-21669CRITICAL9.9A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-21668MEDIUM6.5A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup ...
CVE-2026-21667HIGH8.8A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-21666HIGH8.8A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-3099HIGH7.3A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does...
CVE-2026-2987MEDIUM6.1The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions...
CVE-2026-2514MEDIUM6.1In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to ...
CVE-2026-2513MEDIUM6.1A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks ...
CVE-2026-0809MEDIUM6.3Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-F...
CVE-2026-4040MEDIUM5.5A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the c...
CVE-2026-4039HIGH8.8A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverr...
CVE-2026-3989HIGH7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An at...
CVE-2026-3060CRITICAL9.8SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disagg...
CVE-2026-3059CRITICAL9.8SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, whi...
CVE-2026-3234MEDIUM4.3A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeen...
CVE-2026-2366LOW3.1A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated u...
CVE-2026-4016MEDIUM5.3A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_proce...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now