2026 CVE Vulnerabilities
67,723 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-70200 | CRITICAL | 9.8 | 0.9% | Sep 17, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize... |
| CVE-2026-70009 | CRITICAL | 9.8 | 0.7% | Sep 17, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attac... |
| CVE-2026-69865 | CRITICAL | 10 | 0.8% | Sep 17, 2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elev... |
| CVE-2026-69399 | CRITICAL | 9.8 | 0.9% | Sep 17, 2026 | Azure Arc Elevation of Privilege Vulnerability |
| CVE-2026-68791 | HIGH | 7.5 | 1.0% | Sep 17, 2026 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network... |
| CVE-2026-65323 | — | — | — | Sep 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-55946 | MEDIUM | 5.9 | 0.7% | Sep 17, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-93426 | HIGH | 8.5 | 0.4% | Sep 17, 2026 | SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, ... |
| CVE-2026-93307 | MEDIUM | 4.3 | 0.3% | Sep 17, 2026 | A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Coll... |
| CVE-2026-86688 | HIGH | 7.4 | — | Sep 17, 2026 | Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier ... |
| CVE-2026-78668 | — | — | — | Sep 17, 2026 | Rejected reason: reserved but not needed |
| CVE-2026-76949 | CRITICAL | 9.1 | — | Sep 17, 2026 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a re... |
| CVE-2026-73639 | CRITICAL | 9.1 | 0.2% | Sep 17, 2026 | Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tR... |
| CVE-2026-73638 | MEDIUM | 6.2 | 0.2% | Sep 17, 2026 | Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_... |
| CVE-2026-54767 | CRITICAL | 9.1 | — | Sep 17, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php... |
| CVE-2026-54734 | CRITICAL | 10 | 0.4% | Sep 17, 2026 | Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-suppl... |
| CVE-2026-54671 | HIGH | 8.8 | — | Sep 17, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource arra... |
| CVE-2026-54670 | CRITICAL | 9.1 | 0.6% | Sep 17, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/cont... |
| CVE-2026-54648 | MEDIUM | 6.5 | 0.3% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely ... |
| CVE-2026-54647 | HIGH | 7.2 | 1.9% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates t... |
| CVE-2026-54646 | HIGH | 7.2 | 1.4% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator... |
| CVE-2026-54645 | MEDIUM | 4.8 | 1.1% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, ... |
| CVE-2026-54644 | MEDIUM | 6.1 | 1.1% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip... |
| CVE-2026-54643 | MEDIUM | 5.4 | 0.2% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.ph... |
| CVE-2026-54642 | MEDIUM | 5.3 | 0.3% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now