2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53459 | CRITICAL | 9.3 | 0.4% | Sep 15, 2026 | Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and p... |
| CVE-2026-45579 | CRITICAL | 9.9 | — | Sep 15, 2026 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1... |
| CVE-2026-12351 | CRITICAL | 9.8 | 0.9% | Sep 15, 2026 | IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 L... |
| CVE-2026-11928 | CRITICAL | 9.8 | 0.1% | Sep 15, 2026 | IBM Verify Identity Access is vulnerable to a buffer overflow attack. |
| CVE-2026-11921 | CRITICAL | 9.1 | 0.1% | Sep 15, 2026 | IBM Verify Identity Access containers may not apply management password change operations correctly. |
| CVE-2026-89026 | CRITICAL | 9.8 | 0.7% | Sep 15, 2026 | The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS... |
| CVE-2026-53710 | CRITICAL | 10 | — | Sep 15, 2026 | MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sa... |
| CVE-2026-46488 | CRITICAL | 9.1 | 0.3% | Sep 15, 2026 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w... |
| CVE-2026-91949 | CRITICAL | 9.3 | 0.4% | Sep 15, 2026 | FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated at... |
| CVE-2026-77972 | CRITICAL | 9 | 0.3% | Sep 15, 2026 | Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS respo... |
| CVE-2026-77866 | CRITICAL | 9 | 0.5% | Sep 15, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reac... |
| CVE-2026-55211 | CRITICAL | 9.8 | 0.5% | Sep 15, 2026 | Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fiel... |
| CVE-2026-37152 | CRITICAL | 9.8 | 0.5% | Sep 15, 2026 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access. |
| CVE-2026-88617 | CRITICAL | 9.8 | 0.4% | Sep 15, 2026 | SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to ... |
| CVE-2026-79303 | CRITICAL | 9.9 | 0.2% | Sep 15, 2026 | kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without t... |
| CVE-2026-63696 | CRITICAL | 9.1 | 0.3% | Sep 15, 2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerab... |
| CVE-2026-63695 | CRITICAL | 9.8 | 0.5% | Sep 15, 2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticate... |
| CVE-2026-61549 | CRITICAL | 9 | — | Sep 15, 2026 | Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_op... |
| CVE-2026-59971 | CRITICAL | 10 | — | Sep 15, 2026 | MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2... |
| CVE-2026-55158 | CRITICAL | 9.1 | 0.4% | Sep 15, 2026 | Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1,... |
| CVE-2026-46495 | CRITICAL | 9.2 | 1.1% | Sep 15, 2026 | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/... |
| CVE-2026-39919 | CRITICAL | 9.8 | 0.5% | Sep 15, 2026 | Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjp... |
| CVE-2026-77179 | CRITICAL | 9.4 | 0.2% | Sep 15, 2026 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file... |
| CVE-2026-92079 | CRITICAL | 9.1 | 0.2% | Sep 15, 2026 | Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunde... |
| CVE-2026-92075 | CRITICAL | 9.1 | 0.2% | Sep 15, 2026 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now