2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57138 | CRITICAL | 9.9 | 0.4% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mo... |
| CVE-2026-52824 | CRITICAL | 9.1 | 2.1% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the pub... |
| CVE-2026-62379 | CRITICAL | 9.8 | 1.1% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice P... |
| CVE-2026-62263 | CRITICAL | 9.2 | 0.5% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize ap... |
| CVE-2026-48717 | CRITICAL | 9.1 | 0.3% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler req... |
| CVE-2026-46619 | CRITICAL | 9.3 | 1.0% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authen... |
| CVE-2026-45052 | CRITICAL | 9.3 | 0.3% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receive... |
| CVE-2026-45051 | CRITICAL | 9.2 | 0.5% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serial... |
| CVE-2026-90711 | CRITICAL | 9.1 | 0.2% | Sep 15, 2026 | proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs E... |
| CVE-2026-91003 | CRITICAL | 9.1 | 0.5% | Sep 15, 2026 | A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of th... |
| CVE-2026-91001 | CRITICAL | 9.9 | 0.5% | Sep 15, 2026 | A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of... |
| CVE-2026-90847 | CRITICAL | 9.1 | 2.2% | Sep 15, 2026 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_se... |
| CVE-2026-12944 | CRITICAL | 9.6 | 0.2% | Sep 14, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) ... |
| CVE-2026-86881 | CRITICAL | 9.1 | 0.1% | Sep 14, 2026 | A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and i... |
| CVE-2026-84625 | CRITICAL | 9.1 | 0.4% | Sep 14, 2026 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, mac... |
| CVE-2026-84609 | CRITICAL | 9.8 | 0.2% | Sep 14, 2026 | A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Gold... |
| CVE-2026-84561 | CRITICAL | 9.8 | 0.2% | Sep 14, 2026 | A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS ... |
| CVE-2026-84520 | CRITICAL | 9.8 | 0.1% | Sep 14, 2026 | A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local atta... |
| CVE-2026-67399 | CRITICAL | 9.3 | 0.7% | Sep 14, 2026 | Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute... |
| CVE-2026-65414 | CRITICAL | 9.8 | 1.0% | Sep 14, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.... |
| CVE-2026-65381 | CRITICAL | 10 | 0.2% | Sep 14, 2026 | A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the pro... |
| CVE-2026-53713 | CRITICAL | 9.1 | 0.4% | Sep 14, 2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway... |
| CVE-2026-43790 | CRITICAL | 9.1 | 0.3% | Sep 14, 2026 | The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, ... |
| CVE-2026-55209 | CRITICAL | 9.8 | — | Sep 14, 2026 | resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata i... |
| CVE-2026-54334 | CRITICAL | 9.8 | 0.4% | Sep 14, 2026 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Pri... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now