2026 CVE Vulnerabilities

68,515 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11537MEDIUM4.3IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the fi...
CVE-2026-11381HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to i...
CVE-2026-11378HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a...
CVE-2026-11375HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a...
CVE-2026-10858CRITICAL9.9IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote...
CVE-2026-10853HIGH8.8IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arb...
CVE-2026-10841MEDIUM4.8IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
CVE-2026-10751HIGH7.5IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applicati...
CVE-2026-10747CRITICAL10IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to...
CVE-2026-10744HIGH7.5IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote...
CVE-2026-10575HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a he...
CVE-2026-10030HIGH7.1IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authoriz...
CVE-2026-10027CRITICAL9.8IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow whe...
CVE-2026-93685MEDIUM5.4A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authenti...
CVE-2026-93676LOW3.2xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictio...
CVE-2026-93660MEDIUM6.5SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authe...
CVE-2026-93659HIGH8.1Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a...
CVE-2026-93658HIGH7uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership ...
CVE-2026-93657HIGH7.5hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and R...
CVE-2026-93653MEDIUM5.5A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching t...
CVE-2026-93652HIGH7.5Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause Do...
CVE-2026-93576HIGH7.5A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed ...
CVE-2026-93573MEDIUM6.5A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` ...
CVE-2026-93569HIGH8.2A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 con...
CVE-2026-93568HIGH7.5A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTT...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now