2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72535 | HIGH | 8.6 | — | Aug 11, 2026 | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint... |
| CVE-2026-72534 | HIGH | 8.8 | — | Aug 11, 2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s... |
| CVE-2026-72533 | HIGH | 8.8 | — | Aug 11, 2026 | An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas... |
| CVE-2026-50237 | HIGH | 7.4 | — | Aug 11, 2026 | A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace t... |
| CVE-2026-50236 | HIGH | 7.4 | — | Aug 11, 2026 | An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are... |
| CVE-2026-13739 | HIGH | 8.8 | — | Aug 11, 2026 | A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability relate... |
| CVE-2026-73160 | HIGH | 8.7 | — | Aug 11, 2026 | Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoi... |
| CVE-2026-72694 | HIGH | 7.1 | 0.1% | Aug 11, 2026 | A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low... |
| CVE-2026-72693 | HIGH | 7.8 | 0.1% | Aug 11, 2026 | `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged ... |
| CVE-2026-71217 | HIGH | 7.5 | 0.3% | Aug 11, 2026 | A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON wit... |
| CVE-2026-15567 | HIGH | 7.5 | 0.3% | Aug 11, 2026 | A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token dec... |
| CVE-2026-15565 | HIGH | 7.5 | 0.4% | Aug 11, 2026 | A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on... |
| CVE-2026-15563 | HIGH | 7.4 | 0.3% | Aug 11, 2026 | A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing... |
| CVE-2026-15562 | HIGH | 7.5 | 0.4% | Aug 11, 2026 | A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and... |
| CVE-2026-15561 | HIGH | 7.5 | 0.3% | Aug 11, 2026 | A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at... |
| CVE-2026-15560 | HIGH | 8.1 | 0.4% | Aug 11, 2026 | when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmars... |
| CVE-2026-15556 | HIGH | 8.1 | 0.2% | Aug 11, 2026 | A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching th... |
| CVE-2026-15555 | HIGH | 8.8 | 0.3% | Aug 11, 2026 | A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via ... |
| CVE-2026-15554 | HIGH | 7.4 | 0.2% | Aug 11, 2026 | the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authenti... |
| CVE-2026-19418 | HIGH | 7.3 | 0.2% | Aug 11, 2026 | The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, wher... |
| CVE-2026-16053 | HIGH | 8.5 | 1.0% | Aug 11, 2026 | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Tr... |
| CVE-2026-4757 | HIGH | 7.2 | 0.4% | Aug 11, 2026 | A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege... |
| CVE-2026-8917 | HIGH | 8.4 | 0.1% | Aug 11, 2026 | Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a ... |
| CVE-2026-19424 | HIGH | 8.7 | 0.4% | Aug 11, 2026 | Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated rem... |
| CVE-2026-66763 | HIGH | 7.9 | 0.1% | Aug 11, 2026 | SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects usi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now