2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73370 | CRITICAL | 9.8 | — | Sep 14, 2026 | Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconc... |
| CVE-2026-90937 | CRITICAL | 9.9 | 0.3% | Sep 14, 2026 | froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated cus... |
| CVE-2026-78330 | CRITICAL | 9.8 | — | Sep 14, 2026 | Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT auth... |
| CVE-2026-78299 | CRITICAL | 9.1 | 0.3% | Sep 14, 2026 | In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extr... |
| CVE-2026-77181 | CRITICAL | 9.8 | — | Sep 14, 2026 | Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unab... |
| CVE-2026-77051 | CRITICAL | 9.8 | — | Sep 14, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. ... |
| CVE-2026-75030 | CRITICAL | 9.8 | — | Sep 14, 2026 | Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be abl... |
| CVE-2026-73668 | CRITICAL | 9.8 | — | Sep 14, 2026 | Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Rea... |
| CVE-2026-73579 | CRITICAL | 9.8 | — | Sep 14, 2026 | Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elast... |
| CVE-2026-73470 | CRITICAL | 9.8 | — | Sep 14, 2026 | Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not... |
| CVE-2026-12258 | CRITICAL | 9.2 | 0.4% | Sep 14, 2026 | Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticate... |
| CVE-2026-90919 | CRITICAL | 9.8 | 1.0% | Sep 14, 2026 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_reg... |
| CVE-2026-21391 | CRITICAL | 9.5 | 0.4% | Sep 14, 2026 | An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID ... |
| CVE-2026-90898 | CRITICAL | 9.8 | 0.3% | Sep 14, 2026 | Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that pro... |
| CVE-2026-87802 | CRITICAL | 9.1 | — | Sep 14, 2026 | Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.... |
| CVE-2026-87785 | CRITICAL | 9.1 | — | Sep 14, 2026 | Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT... |
| CVE-2026-86460 | CRITICAL | 9.8 | — | Sep 14, 2026 | Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue... |
| CVE-2026-82232 | CRITICAL | 9.8 | — | Sep 14, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. ... |
| CVE-2026-90703 | CRITICAL | 9.1 | 2.8% | Sep 14, 2026 | A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafr... |
| CVE-2026-90702 | CRITICAL | 9.1 | — | Sep 14, 2026 | A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. Thi... |
| CVE-2026-90699 | CRITICAL | 9.9 | 1.6% | Sep 14, 2026 | A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/... |
| CVE-2026-90693 | CRITICAL | 9.9 | 0.5% | Sep 14, 2026 | A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings.... |
| CVE-2026-90692 | CRITICAL | 9.9 | 0.5% | Sep 14, 2026 | A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the compon... |
| CVE-2026-85192 | CRITICAL | 9.4 | 0.5% | Sep 14, 2026 | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension fo... |
| CVE-2026-82787 | CRITICAL | 9.8 | 0.4% | Sep 14, 2026 | Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now