2026 CVE Vulnerabilities

67,720 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93452HIGH7.5snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wr...
CVE-2026-93451MEDIUM6.5snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allo...
CVE-2026-93450HIGH7.5go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serializatio...
CVE-2026-93309MEDIUM4.3A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of t...
CVE-2026-93308MEDIUM4.3A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of ...
CVE-2026-85887HIGH7.7Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informat...
CVE-2026-85878CRITICAL9.9Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a netwo...
CVE-2026-83946MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthori...
CVE-2026-69843CRITICAL10Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwo...
CVE-2026-62874CRITICAL10Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges ov...
CVE-2026-2585MEDIUM6.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ para...
CVE-2026-18441MEDIUM4.3The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to I...
CVE-2026-93436HIGH7.5vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode di...
CVE-2026-93435HIGH7.5redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious ...
CVE-2026-87886HIGH7.8Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin ...
CVE-2026-87701CRITICAL9.6Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB al...
CVE-2026-85917HIGH7.5Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a netw...
CVE-2026-85889CRITICAL9.8Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges o...
CVE-2026-85885HIGH8.8Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized...
CVE-2026-83944CRITICAL9.1Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-78501HIGH7.4Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business ...
CVE-2026-77903HIGH8.1Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a ne...
CVE-2026-70200CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize...
CVE-2026-70009CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attac...
CVE-2026-69865CRITICAL10Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elev...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now