2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54333 | CRITICAL | 9.8 | — | Sep 14, 2026 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Pri... |
| CVE-2026-50006 | CRITICAL | 9.1 | 1.0% | Sep 14, 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL fro... |
| CVE-2026-18119 | CRITICAL | 9 | 0.3% | Sep 14, 2026 | Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page C... |
| CVE-2026-16338 | CRITICAL | 9.9 | 0.6% | Sep 14, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbi... |
| CVE-2026-59178 | CRITICAL | 9.8 | — | Sep 14, 2026 | ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the d... |
| CVE-2026-90945 | CRITICAL | 9.8 | 0.5% | Sep 14, 2026 | Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configura... |
| CVE-2026-90942 | CRITICAL | 9.6 | 0.2% | Sep 14, 2026 | Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /a... |
| CVE-2026-57578 | CRITICAL | 9.2 | — | Sep 14, 2026 | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, Author... |
| CVE-2026-76461 | CRITICAL | 9.8 | — | Sep 14, 2026 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthentic... |
| CVE-2026-76443 | CRITICAL | 9.8 | 0.4% | Sep 14, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc... |
| CVE-2026-76441 | CRITICAL | 9.8 | 0.5% | Sep 14, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc... |
| CVE-2026-76440 | CRITICAL | 9.8 | 0.4% | Sep 14, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc... |
| CVE-2026-20353 | CRITICAL | 9.8 | 0.4% | Sep 14, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc... |
| CVE-2026-61534 | CRITICAL | 9.1 | — | Sep 14, 2026 | Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use a... |
| CVE-2026-57145 | CRITICAL | 9.1 | 0.4% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-cont... |
| CVE-2026-57131 | CRITICAL | 9.8 | 1.0% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.... |
| CVE-2026-57127 | CRITICAL | 9.8 | 0.9% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddlewar... |
| CVE-2026-57124 | CRITICAL | 9.8 | 0.6% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect ... |
| CVE-2026-82435 | CRITICAL | 9.8 | — | Sep 14, 2026 | Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline a... |
| CVE-2026-82431 | CRITICAL | 9.8 | — | Sep 14, 2026 | Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty... |
| CVE-2026-57125 | CRITICAL | 9.8 | 0.4% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST ... |
| CVE-2026-57123 | CRITICAL | 9.8 | 0.5% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_se... |
| CVE-2026-90961 | CRITICAL | 9.3 | 0.5% | Sep 14, 2026 | The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuth... |
| CVE-2026-82441 | CRITICAL | 9.1 | — | Sep 14, 2026 | Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, whi... |
| CVE-2026-82439 | CRITICAL | 9.8 | — | Sep 14, 2026 | Description The DRPC server kept a map from function name to request queue and created an entry the first time a functi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now