2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-73370CRITICAL9.8Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconc...
CVE-2026-90937CRITICAL9.9froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated cus...
CVE-2026-78330CRITICAL9.8Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT auth...
CVE-2026-78299CRITICAL9.1In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extr...
CVE-2026-77181CRITICAL9.8Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unab...
CVE-2026-77051CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. ...
CVE-2026-75030CRITICAL9.8Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be abl...
CVE-2026-73668CRITICAL9.8Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Rea...
CVE-2026-73579CRITICAL9.8Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elast...
CVE-2026-73470CRITICAL9.8Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not...
CVE-2026-12258CRITICAL9.2Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticate...
CVE-2026-90919CRITICAL9.8LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_reg...
CVE-2026-21391CRITICAL9.5An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID ...
CVE-2026-90898CRITICAL9.8Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that pro...
CVE-2026-87802CRITICAL9.1Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2....
CVE-2026-87785CRITICAL9.1Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT...
CVE-2026-86460CRITICAL9.8Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue...
CVE-2026-82232CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. ...
CVE-2026-90703CRITICAL9.1A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafr...
CVE-2026-90702CRITICAL9.1A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. Thi...
CVE-2026-90699CRITICAL9.9A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/...
CVE-2026-90693CRITICAL9.9A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings....
CVE-2026-90692CRITICAL9.9A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the compon...
CVE-2026-85192CRITICAL9.4Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension fo...
CVE-2026-82787CRITICAL9.8Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now