2026 CVE Vulnerabilities

68,213 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-83946MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthori...
CVE-2026-69843CRITICAL10Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwo...
CVE-2026-62874CRITICAL10Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges ov...
CVE-2026-2585MEDIUM6.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ para...
CVE-2026-18441MEDIUM4.3The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to I...
CVE-2026-93436HIGH7.5vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode di...
CVE-2026-93435HIGH7.5redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious ...
CVE-2026-87886HIGH7.8Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin ...
CVE-2026-87701CRITICAL9.6Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB al...
CVE-2026-85917HIGH7.5Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a netw...
CVE-2026-85889CRITICAL9.8Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges o...
CVE-2026-85885HIGH8.8Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized...
CVE-2026-83944CRITICAL9.1Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-78501HIGH7.4Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business ...
CVE-2026-77903HIGH8.1Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a ne...
CVE-2026-70200CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize...
CVE-2026-70009CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attac...
CVE-2026-69865CRITICAL10Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elev...
CVE-2026-69399CRITICAL9.8Azure Arc Elevation of Privilege Vulnerability
CVE-2026-68791HIGH7.5Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network...
CVE-2026-65323——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-55946MEDIUM5.9Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-93426HIGH8.5SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, ...
CVE-2026-93307MEDIUM4.3A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Coll...
CVE-2026-86688HIGH7.4Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now