2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-18236CRITICAL9.3A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker wh...
CVE-2026-8338CRITICAL9.2A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026....
CVE-2026-54680CRITICAL9.9Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd...
CVE-2026-13697CRITICAL9.1undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 an...
CVE-2026-67192CRITICAL9.2Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthentic...
CVE-2026-67191CRITICAL9.8Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unaut...
CVE-2026-60113CRITICAL9.8AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnera...
CVE-2026-60112CRITICAL9.8AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthen...
CVE-2026-54735CRITICAL10Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0...
CVE-2026-65888CRITICAL9.8Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows acto...
CVE-2026-65887CRITICAL9.8Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method...
CVE-2026-9177CRITICAL9.4A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se...
CVE-2026-65890CRITICAL9.8Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthe...
CVE-2026-65884CRITICAL9.8Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provide...
CVE-2026-0667CRITICAL9.3CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d...
CVE-2026-65883CRITICAL9.8Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo...
CVE-2026-14900CRITICAL9.8The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i...
CVE-2026-14488CRITICAL9.1The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the...
CVE-2026-59243CRITICAL9.8The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacke...
CVE-2026-58185CRITICAL9.8The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 t...
CVE-2026-58179CRITICAL9.8The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affec...
CVE-2026-58177CRITICAL9.8The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This is...
CVE-2026-58163CRITICAL9.1Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue af...
CVE-2026-58162CRITICAL10The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue a...
CVE-2026-58161CRITICAL9.2Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now