2026 CVE Vulnerabilities

69,550 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29113MEDIUM4.3Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token e...
CVE-2026-28495HIGH8.8GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allo...
CVE-2026-27825HIGH8MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0....
CVE-2026-26330HIGH7.5Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit f...
CVE-2026-26311MEDIUM5.9Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerabili...
CVE-2026-26310HIGH7.5Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::ge...
CVE-2026-26309MEDIUM5.3Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write...
CVE-2026-26308HIGH8.2Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Rol...
CVE-2026-26123MEDIUM5.5Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
CVE-2026-23868MEDIUM5.1Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect erro...
CVE-2026-3370——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-28292CRITICAL9.8`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through ...
CVE-2026-27826HIGH8.2MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0....
CVE-2026-27281MEDIUM5.5DNG SDK versions 1.7.1 2471 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead ...
CVE-2026-27280HIGH7.8DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr...
CVE-2026-27279HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-27277HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2026-27276HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2026-27275HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-27274HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-27273HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-27269HIGH7.8Premiere Pro versions 25.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, ...
CVE-2026-27219MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to...
CVE-2026-27218MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27217MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now