2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-72535HIGH8.6A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint...
CVE-2026-72534HIGH8.8A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s...
CVE-2026-72533HIGH8.8An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas...
CVE-2026-50237HIGH7.4A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace t...
CVE-2026-50236HIGH7.4An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are...
CVE-2026-13739HIGH8.8A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability relate...
CVE-2026-73160HIGH8.7Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoi...
CVE-2026-72694HIGH7.1A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low...
CVE-2026-72693HIGH7.8`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged ...
CVE-2026-71217HIGH7.5A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON wit...
CVE-2026-15567HIGH7.5A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token dec...
CVE-2026-15565HIGH7.5A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on...
CVE-2026-15563HIGH7.4A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing...
CVE-2026-15562HIGH7.5A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and...
CVE-2026-15561HIGH7.5A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at...
CVE-2026-15560HIGH8.1when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmars...
CVE-2026-15556HIGH8.1A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching th...
CVE-2026-15555HIGH8.8A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via ...
CVE-2026-15554HIGH7.4the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authenti...
CVE-2026-19418HIGH7.3The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, wher...
CVE-2026-16053HIGH8.5Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Tr...
CVE-2026-4757HIGH7.2A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege...
CVE-2026-8917HIGH8.4Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a ...
CVE-2026-19424HIGH8.7Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated rem...
CVE-2026-66763HIGH7.9SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects usi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now