2026 CVE Vulnerabilities
70,500 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1565 | HIGH | 8.8 | 0.5% | Feb 26, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-1241 | HIGH | 8.7 | 0.3% | Feb 26, 2026 | The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web manage... |
| CVE-2026-26938 | HIGH | 7.7 | 0.3% | Feb 26, 2026 | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which cou... |
| CVE-2026-26937 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Dat... |
| CVE-2026-22722 | MEDIUM | 6.1 | 0.1% | Feb 26, 2026 | A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null poi... |
| CVE-2026-22715 | MEDIUM | 5.9 | 0.2% | Feb 26, 2026 | VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malic... |
| CVE-2026-26936 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial ... |
| CVE-2026-26935 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Servi... |
| CVE-2026-26934 | MEDIUM | 6.5 | 0.3% | Feb 26, 2026 | Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-on... |
| CVE-2026-26932 | HIGH | 7.5 | 0.5% | Feb 26, 2026 | Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service ... |
| CVE-2026-26682 | HIGH | 7.8 | 0.2% | Feb 26, 2026 | An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java compo... |
| CVE-2026-26227 | MEDIUM | 6.3 | 0.3% | Feb 26, 2026 | VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature du... |
| CVE-2026-23750 | HIGH | 8.1 | 0.2% | Feb 26, 2026 | Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certific... |
| CVE-2026-23749 | LOW | 2.9 | 0.2% | Feb 26, 2026 | Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to impr... |
| CVE-2026-23748 | MEDIUM | 6.3 | 0.3% | Feb 26, 2026 | Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit d7f55b38, contain an out-of-bounds read in LightDB ... |
| CVE-2026-23747 | MEDIUM | 6.3 | 0.3% | Feb 26, 2026 | Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit 48f521b, contain a stack-based buffer overflow in P... |
| CVE-2026-28296 | MEDIUM | 4.3 | 0.4% | Feb 26, 2026 | A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplyi... |
| CVE-2026-28295 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrar... |
| CVE-2026-26265 | HIGH | 7.5 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerabil... |
| CVE-2026-26228 | MEDIUM | 4.9 | 0.3% | Feb 26, 2026 | VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server rout... |
| CVE-2026-26207 | MEDIUM | 5.4 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy`... |
| CVE-2026-26078 | HIGH | 7.5 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_... |
| CVE-2026-3071 | HIGH | 8.4 | 0.2% | Feb 26, 2026 | Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to ar... |
| CVE-2026-2244 | HIGH | 8.4 | 0.2% | Feb 26, 2026 | A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid ... |
| CVE-2026-26077 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook en... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now