2026 CVE Vulnerabilities
43,253 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17688 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the render... |
| CVE-2026-17687 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the render... |
| CVE-2026-17684 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a re... |
| CVE-2026-17682 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rend... |
| CVE-2026-17681 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allo... |
| CVE-2026-17680 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had comp... |
| CVE-2026-17676 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who h... |
| CVE-2026-17675 | CRITICAL | 9.6 | 0.3% | Jul 30, 2026 | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the r... |
| CVE-2026-17673 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rende... |
| CVE-2026-17672 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attack... |
| CVE-2026-17671 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker wh... |
| CVE-2026-17670 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the render... |
| CVE-2026-17669 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker ... |
| CVE-2026-17666 | CRITICAL | 9.1 | 0.2% | Jul 30, 2026 | Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network pos... |
| CVE-2026-17656 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-17655 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to... |
| CVE-2026-17652 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the render... |
| CVE-2026-17651 | CRITICAL | 9.6 | 0.4% | Jul 30, 2026 | Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote a... |
| CVE-2026-67595 | CRITICAL | 9.2 | 0.4% | Jul 29, 2026 | VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template re... |
| CVE-2026-67429 | CRITICAL | 10 | 0.5% | Jul 29, 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fi... |
| CVE-2026-67426 | CRITICAL | 9.3 | 0.3% | Jul 29, 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verifica... |
| CVE-2026-16326 | CRITICAL | 10 | — | Jul 29, 2026 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may all... |
| CVE-2026-14529 | CRITICAL | 9.8 | 0.3% | Jul 29, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 t... |
| CVE-2026-41939 | CRITICAL | 9.8 | 0.8% | Jul 29, 2026 | Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final manag... |
| CVE-2026-18236 | CRITICAL | 9.3 | — | Jul 29, 2026 | A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker wh... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now