2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18236 | CRITICAL | 9.3 | — | Jul 29, 2026 | A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker wh... |
| CVE-2026-8338 | CRITICAL | 9.2 | 0.3% | Jul 29, 2026 | A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.... |
| CVE-2026-54680 | CRITICAL | 9.9 | — | Jul 29, 2026 | Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd... |
| CVE-2026-13697 | CRITICAL | 9.1 | 0.3% | Jul 29, 2026 | undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 an... |
| CVE-2026-67192 | CRITICAL | 9.2 | 0.6% | Jul 29, 2026 | Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthentic... |
| CVE-2026-67191 | CRITICAL | 9.8 | 0.6% | Jul 29, 2026 | Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unaut... |
| CVE-2026-60113 | CRITICAL | 9.8 | 0.4% | Jul 29, 2026 | AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnera... |
| CVE-2026-60112 | CRITICAL | 9.8 | 0.4% | Jul 29, 2026 | AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthen... |
| CVE-2026-54735 | CRITICAL | 10 | 0.4% | Jul 29, 2026 | Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0... |
| CVE-2026-65888 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows acto... |
| CVE-2026-65887 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method... |
| CVE-2026-9177 | CRITICAL | 9.4 | 0.3% | Jul 29, 2026 | A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se... |
| CVE-2026-65890 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthe... |
| CVE-2026-65884 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provide... |
| CVE-2026-0667 | CRITICAL | 9.3 | 0.4% | Jul 29, 2026 | CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d... |
| CVE-2026-65883 | CRITICAL | 9.8 | 0.5% | Jul 29, 2026 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo... |
| CVE-2026-14900 | CRITICAL | 9.8 | — | Jul 29, 2026 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i... |
| CVE-2026-14488 | CRITICAL | 9.1 | — | Jul 29, 2026 | The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the... |
| CVE-2026-59243 | CRITICAL | 9.8 | 0.5% | Jul 29, 2026 | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacke... |
| CVE-2026-58185 | CRITICAL | 9.8 | 0.3% | Jul 29, 2026 | The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 t... |
| CVE-2026-58179 | CRITICAL | 9.8 | 0.4% | Jul 29, 2026 | The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affec... |
| CVE-2026-58177 | CRITICAL | 9.8 | 0.3% | Jul 29, 2026 | The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This is... |
| CVE-2026-58163 | CRITICAL | 9.1 | 0.4% | Jul 29, 2026 | Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue af... |
| CVE-2026-58162 | CRITICAL | 10 | 0.2% | Jul 29, 2026 | The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue a... |
| CVE-2026-58161 | CRITICAL | 9.2 | 0.4% | Jul 29, 2026 | Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now