2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12974 | HIGH | 7.9 | — | Sep 23, 2026 | A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Secu... |
| CVE-2026-95676 | HIGH | 7.4 | 0.5% | Sep 23, 2026 | A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authenticat... |
| CVE-2026-86247 | HIGH | 7.4 | — | Sep 23, 2026 | Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirement... |
| CVE-2026-86243 | HIGH | 7.5 | — | Sep 23, 2026 | Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a Do... |
| CVE-2026-76980 | HIGH | 7.4 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vul... |
| CVE-2026-76979 | HIGH | 7.7 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vu... |
| CVE-2026-76978 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection... |
| CVE-2026-75825 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable ... |
| CVE-2026-87022 | HIGH | 7.5 | — | Sep 23, 2026 | Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling wh... |
| CVE-2026-84791 | HIGH | 7.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Con... |
| CVE-2026-84789 | HIGH | 7.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Con... |
| CVE-2026-84787 | HIGH | 8.1 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalat... |
| CVE-2026-79677 | HIGH | 7.5 | — | Sep 23, 2026 | Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allo... |
| CVE-2026-78437 | HIGH | 7.3 | — | Sep 23, 2026 | Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause on... |
| CVE-2026-78383 | HIGH | 7.5 | — | Sep 23, 2026 | Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP reques... |
| CVE-2026-77791 | HIGH | 7.5 | — | Sep 23, 2026 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS... |
| CVE-2026-77762 | HIGH | 8.1 | — | Sep 23, 2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc... |
| CVE-2026-75973 | HIGH | 7.3 | — | Sep 23, 2026 | Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfig... |
| CVE-2026-15358 | HIGH | 7.5 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unautho... |
| CVE-2026-14913 | HIGH | 8.8 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vu... |
| CVE-2026-12370 | HIGH | 7.6 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vu... |
| CVE-2026-96455 | HIGH | 8.8 | — | Sep 23, 2026 | The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in ... |
| CVE-2026-96442 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends oth... |
| CVE-2026-5695 | HIGH | 8.4 | 0.3% | Sep 23, 2026 | Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users ... |
| CVE-2026-96454 | HIGH | 8.2 | 0.5% | Sep 23, 2026 | Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings fro... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now