2026 CVE Vulnerabilities
68,213 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-83946 | MEDIUM | 6.1 | 0.6% | Sep 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthori... |
| CVE-2026-69843 | CRITICAL | 10 | 0.9% | Sep 18, 2026 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwo... |
| CVE-2026-62874 | CRITICAL | 10 | 0.3% | Sep 18, 2026 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges ov... |
| CVE-2026-2585 | MEDIUM | 6.4 | 0.2% | Sep 18, 2026 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ para... |
| CVE-2026-18441 | MEDIUM | 4.3 | 0.2% | Sep 18, 2026 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to I... |
| CVE-2026-93436 | HIGH | 7.5 | — | Sep 17, 2026 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode di... |
| CVE-2026-93435 | HIGH | 7.5 | — | Sep 17, 2026 | redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious ... |
| CVE-2026-87886 | HIGH | 7.8 | — | Sep 17, 2026 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin ... |
| CVE-2026-87701 | CRITICAL | 9.6 | 0.8% | Sep 17, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB al... |
| CVE-2026-85917 | HIGH | 7.5 | 1.0% | Sep 17, 2026 | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a netw... |
| CVE-2026-85889 | CRITICAL | 9.8 | 0.9% | Sep 17, 2026 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges o... |
| CVE-2026-85885 | HIGH | 8.8 | 1.0% | Sep 17, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized... |
| CVE-2026-83944 | CRITICAL | 9.1 | 0.8% | Sep 17, 2026 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-78501 | HIGH | 7.4 | — | Sep 17, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business ... |
| CVE-2026-77903 | HIGH | 8.1 | 0.7% | Sep 17, 2026 | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a ne... |
| CVE-2026-70200 | CRITICAL | 9.8 | 0.9% | Sep 17, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize... |
| CVE-2026-70009 | CRITICAL | 9.8 | 0.7% | Sep 17, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attac... |
| CVE-2026-69865 | CRITICAL | 10 | 0.8% | Sep 17, 2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elev... |
| CVE-2026-69399 | CRITICAL | 9.8 | 0.9% | Sep 17, 2026 | Azure Arc Elevation of Privilege Vulnerability |
| CVE-2026-68791 | HIGH | 7.5 | 1.0% | Sep 17, 2026 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network... |
| CVE-2026-65323 | — | — | — | Sep 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-55946 | MEDIUM | 5.9 | 0.7% | Sep 17, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-93426 | HIGH | 8.5 | 0.4% | Sep 17, 2026 | SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, ... |
| CVE-2026-93307 | MEDIUM | 4.3 | 0.3% | Sep 17, 2026 | A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Coll... |
| CVE-2026-86688 | HIGH | 7.4 | — | Sep 17, 2026 | Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now