2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-50737CRITICAL9When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's...
CVE-2026-50736CRITICAL9The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscrib...
CVE-2026-16498CRITICAL10The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-H...
CVE-2026-67174CRITICAL9.2Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering...
CVE-2026-66713CRITICAL9.8Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Ap...
CVE-2026-65880CRITICAL10Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form proce...
CVE-2026-16462CRITICAL9.8In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker ...
CVE-2026-11841CRITICAL9.4An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac...
CVE-2026-15014CRITICAL9.8The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-11756CRITICAL10A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3...
CVE-2026-14545CRITICAL9.8The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password throu...
CVE-2026-66824CRITICAL9.2A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the...
CVE-2026-64775CRITICAL9.8A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26...
CVE-2026-64774CRITICAL9.8An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS...
CVE-2026-64772CRITICAL9.8An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26...
CVE-2026-64771CRITICAL9.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Se...
CVE-2026-64770CRITICAL9.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26....
CVE-2026-64769CRITICAL9.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26....
CVE-2026-64767CRITICAL9.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma...
CVE-2026-64762CRITICAL9.8An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS So...
CVE-2026-64751CRITICAL9.8A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, m...
CVE-2026-64746CRITICAL9.8An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Ta...
CVE-2026-64740CRITICAL9.3A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in i...
CVE-2026-64738CRITICAL9.8A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonom...
CVE-2026-64733CRITICAL9.8This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now