2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101060 | HIGH | 8.2 | — | Sep 27, 2026 | python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_... |
| CVE-2026-101059 | HIGH | 7.1 | — | Sep 27, 2026 | utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attacker... |
| CVE-2026-101058 | MEDIUM | 6.9 | — | Sep 27, 2026 | python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manu... |
| CVE-2026-101057 | LOW | 3.1 | — | Sep 27, 2026 | utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a cal... |
| CVE-2026-101056 | MEDIUM | 5.3 | — | Sep 27, 2026 | Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID.... |
| CVE-2026-101051 | LOW | 3.1 | — | Sep 27, 2026 | Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated use... |
| CVE-2026-101048 | MEDIUM | 5.4 | — | Sep 27, 2026 | Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/... |
| CVE-2026-101047 | MEDIUM | 5.3 | — | Sep 27, 2026 | Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enter... |
| CVE-2026-101046 | LOW | 3.1 | — | Sep 27, 2026 | Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities... |
| CVE-2026-101045 | HIGH | 8 | — | Sep 27, 2026 | Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests gen... |
| CVE-2026-101044 | HIGH | 7.1 | — | Sep 27, 2026 | pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.... |
| CVE-2026-101043 | HIGH | 7.4 | — | Sep 27, 2026 | pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the htt... |
| CVE-2026-88778 | HIGH | 7.5 | — | Sep 27, 2026 | Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This i... |
| CVE-2026-88777 | CRITICAL | 9.8 | 0.4% | Sep 27, 2026 | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects AD... |
| CVE-2026-88776 | CRITICAL | 9.8 | — | Sep 27, 2026 | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC... |
| CVE-2026-88775 | CRITICAL | 9.8 | 0.4% | Sep 27, 2026 | Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1... |
| CVE-2026-88774 | HIGH | 7.2 | 0.2% | Sep 27, 2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 1... |
| CVE-2026-88773 | CRITICAL | 10 | 0.4% | Sep 27, 2026 | Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC a... |
| CVE-2026-88772 | HIGH | 8.1 | — | Sep 27, 2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 1... |
| CVE-2026-88771 | CRITICAL | 9.8 | — | Sep 27, 2026 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: b... |
| CVE-2026-101050 | MEDIUM | 6.5 | — | Sep 27, 2026 | Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credent... |
| CVE-2026-101049 | MEDIUM | 6.5 | — | Sep 27, 2026 | Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing... |
| CVE-2026-101042 | MEDIUM | 6.4 | — | Sep 27, 2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-ba... |
| CVE-2026-101041 | MEDIUM | 6.3 | 0.2% | Sep 27, 2026 | The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check... |
| CVE-2026-101033 | MEDIUM | 4.3 | — | Sep 27, 2026 | KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now