2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92071 | CRITICAL | 9.6 | 0.1% | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire... |
| CVE-2026-92066 | CRITICAL | 9.8 | 0.1% | Sep 15, 2026 | Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
| CVE-2026-92061 | CRITICAL | 9.8 | 0.1% | Sep 15, 2026 | Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156... |
| CVE-2026-92059 | CRITICAL | 9.3 | 0.1% | Sep 15, 2026 | Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153... |
| CVE-2026-92057 | CRITICAL | 9.1 | 0.2% | Sep 15, 2026 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ... |
| CVE-2026-92051 | CRITICAL | 9.1 | 0.1% | Sep 15, 2026 | Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunder... |
| CVE-2026-92050 | CRITICAL | 9.1 | 0.1% | Sep 15, 2026 | Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunder... |
| CVE-2026-92048 | CRITICAL | 9 | 0.2% | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire... |
| CVE-2026-92045 | CRITICAL | 9.6 | 0.2% | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156... |
| CVE-2026-92041 | CRITICAL | 9.1 | 0.2% | Sep 15, 2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thun... |
| CVE-2026-92038 | CRITICAL | 9.1 | 0.2% | Sep 15, 2026 | Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.... |
| CVE-2026-92037 | CRITICAL | 9.8 | 0.1% | Sep 15, 2026 | Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbi... |
| CVE-2026-92036 | CRITICAL | 9.8 | 0.1% | Sep 15, 2026 | Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunder... |
| CVE-2026-92035 | CRITICAL | 9.6 | 0.2% | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 1... |
| CVE-2026-92034 | CRITICAL | 9.1 | 0.1% | Sep 15, 2026 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
| CVE-2026-92032 | CRITICAL | 9.6 | 0.2% | Sep 15, 2026 | Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ES... |
| CVE-2026-92018 | CRITICAL | 9.6 | 0.2% | Sep 15, 2026 | Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firef... |
| CVE-2026-91998 | CRITICAL | 9.9 | 0.4% | Sep 15, 2026 | Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with... |
| CVE-2026-91995 | CRITICAL | 9.1 | 0.9% | Sep 15, 2026 | pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verif... |
| CVE-2026-89308 | CRITICAL | 9.3 | 3.0% | Sep 15, 2026 | An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to exec... |
| CVE-2026-57148 | CRITICAL | 9.8 | 0.4% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the p... |
| CVE-2026-57147 | CRITICAL | 9.8 | 0.8% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public ... |
| CVE-2026-57141 | CRITICAL | 9.8 | 0.8% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-m... |
| CVE-2026-57140 | CRITICAL | 9.4 | 0.6% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the ... |
| CVE-2026-57139 | CRITICAL | 9.8 | 0.4% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/serve... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now