2026 CVE Vulnerabilities
68,180 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77170 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without va... |
| CVE-2026-77169 | MEDIUM | 6.5 | — | Sep 18, 2026 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed... |
| CVE-2026-77164 | MEDIUM | 6.2 | — | Sep 18, 2026 | Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote insta... |
| CVE-2026-68493 | LOW | 3.1 | — | Sep 18, 2026 | After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships ... |
| CVE-2026-93312 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/J... |
| CVE-2026-93311 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFun... |
| CVE-2026-93310 | MEDIUM | 5.3 | — | Sep 18, 2026 | A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collect... |
| CVE-2026-79954 | HIGH | 8.7 | — | Sep 18, 2026 | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiv... |
| CVE-2026-93454 | MEDIUM | 5.4 | 0.2% | Sep 18, 2026 | Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plu... |
| CVE-2026-93453 | HIGH | 8.3 | 0.3% | Sep 18, 2026 | SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing u... |
| CVE-2026-93452 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wr... |
| CVE-2026-93451 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allo... |
| CVE-2026-93450 | HIGH | 7.5 | 0.7% | Sep 18, 2026 | go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serializatio... |
| CVE-2026-93309 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of t... |
| CVE-2026-93308 | MEDIUM | 4.3 | — | Sep 18, 2026 | A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of ... |
| CVE-2026-85887 | HIGH | 7.7 | — | Sep 18, 2026 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informat... |
| CVE-2026-85878 | CRITICAL | 9.9 | 0.8% | Sep 18, 2026 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a netwo... |
| CVE-2026-83946 | MEDIUM | 6.1 | 0.6% | Sep 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthori... |
| CVE-2026-69843 | CRITICAL | 10 | 0.9% | Sep 18, 2026 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwo... |
| CVE-2026-62874 | CRITICAL | 10 | 0.3% | Sep 18, 2026 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges ov... |
| CVE-2026-2585 | MEDIUM | 6.4 | 0.2% | Sep 18, 2026 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ para... |
| CVE-2026-18441 | MEDIUM | 4.3 | 0.2% | Sep 18, 2026 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to I... |
| CVE-2026-93436 | HIGH | 7.5 | — | Sep 17, 2026 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode di... |
| CVE-2026-93435 | HIGH | 7.5 | — | Sep 17, 2026 | redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious ... |
| CVE-2026-87886 | HIGH | 7.8 | — | Sep 17, 2026 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now