2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76371 | LOW | 2.7 | 0.2% | Aug 19, 2026 | In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could r... |
| CVE-2026-76369 | LOW | 2.7 | 0.3% | Aug 19, 2026 | In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Auto... |
| CVE-2026-76368 | LOW | 2.7 | 0.2% | Aug 19, 2026 | In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view meta... |
| CVE-2026-76361 | LOW | 2.7 | 0.2% | Aug 19, 2026 | In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../c... |
| CVE-2026-76348 | LOW | 3.8 | 0.2% | Aug 19, 2026 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the... |
| CVE-2026-75476 | LOW | 3.1 | 0.2% | Aug 19, 2026 | Tanium addressed a compression bomb vulnerability in Threat Response. |
| CVE-2026-68554 | LOW | 2.3 | 0.1% | Aug 19, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append att... |
| CVE-2026-11617 | LOW | 3.1 | 0.2% | Aug 19, 2026 | Tanium addressed a compression bomb vulnerability in Findings. |
| CVE-2026-61712 | LOW | 2.3 | 0.4% | Aug 19, 2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P... |
| CVE-2026-16891 | LOW | 3.3 | 0.1% | Aug 19, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out... |
| CVE-2026-16890 | LOW | 3.6 | 0.1% | Aug 19, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a de... |
| CVE-2026-16888 | LOW | 3.7 | 0.5% | Aug 19, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a pat... |
| CVE-2026-73829 | LOW | 3.7 | 0.2% | Aug 19, 2026 | Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one c... |
| CVE-2026-75583 | LOW | 3.5 | 0.3% | Aug 19, 2026 | keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerab... |
| CVE-2026-65610 | LOW | 2.4 | 0.1% | Aug 19, 2026 | nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influenc... |
| CVE-2026-65609 | LOW | 2.4 | 0.1% | Aug 19, 2026 | nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields de... |
| CVE-2026-49423 | LOW | 3.3 | 0.1% | Aug 19, 2026 | When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index ... |
| CVE-2026-49431 | LOW | 3.3 | 0.1% | Aug 19, 2026 | The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is... |
| CVE-2026-49426 | LOW | 3.3 | 0.1% | Aug 19, 2026 | When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup f... |
| CVE-2026-19406 | LOW | 2.7 | 0.2% | Aug 19, 2026 | The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to t... |
| CVE-2026-14826 | LOW | 2.7 | 0.2% | Aug 19, 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the RE... |
| CVE-2026-14825 | LOW | 2.7 | 0.2% | Aug 19, 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before sa... |
| CVE-2026-13173 | LOW | 2.7 | 0.2% | Aug 19, 2026 | The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before ass... |
| CVE-2026-76014 | LOW | 3.3 | 0.1% | Aug 19, 2026 | A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/w... |
| CVE-2026-76042 | LOW | 3.1 | 0.3% | Aug 18, 2026 | Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now