2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-88832 | HIGH | 7.3 | 0.1% | Sep 23, 2026 | BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow wh... |
| CVE-2026-88830 | HIGH | 7.5 | — | Sep 23, 2026 | A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow ... |
| CVE-2026-6668 | HIGH | 7.5 | — | Sep 23, 2026 | Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker... |
| CVE-2026-19888 | HIGH | 7.5 | — | Sep 23, 2026 | Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows ... |
| CVE-2026-96673 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated ... |
| CVE-2026-93769 | HIGH | 7.2 | — | Sep 23, 2026 | HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegate... |
| CVE-2026-79310 | HIGH | 8.5 | 0.7% | Sep 23, 2026 | webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into execut... |
| CVE-2026-19179 | HIGH | 8.2 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database querie... |
| CVE-2026-18875 | HIGH | 7.3 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook ... |
| CVE-2026-18490 | HIGH | 8.8 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via ... |
| CVE-2026-18185 | HIGH | 7.3 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive informati... |
| CVE-2026-18184 | HIGH | 7.4 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati... |
| CVE-2026-18181 | HIGH | 8.1 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and ... |
| CVE-2026-96609 | HIGH | 7.1 | 0.2% | Sep 23, 2026 | Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console lo... |
| CVE-2026-96275 | HIGH | 8.8 | 0.4% | Sep 23, 2026 | A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host f... |
| CVE-2026-73591 | HIGH | 7.5 | 0.3% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Infor... |
| CVE-2026-73588 | HIGH | 7.4 | 0.2% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Cr... |
| CVE-2026-55610 | HIGH | 8.7 | — | Sep 23, 2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and... |
| CVE-2026-96512 | HIGH | 7.8 | 0.1% | Sep 23, 2026 | A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps th... |
| CVE-2026-86683 | HIGH | 8.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy s... |
| CVE-2026-86681 | HIGH | 7.6 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue t... |
| CVE-2026-86679 | HIGH | 7.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue t... |
| CVE-2026-86678 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administ... |
| CVE-2026-86677 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized S... |
| CVE-2026-18177 | HIGH | 7.1 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payme... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now