2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77269 | MEDIUM | 6.5 | 0.4% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th... |
| CVE-2026-77268 | MEDIUM | 5.5 | 0.1% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th... |
| CVE-2026-77266 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, up... |
| CVE-2026-77249 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Ji... |
| CVE-2026-76194 | MEDIUM | 4.3 | — | Sep 22, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur... |
| CVE-2026-76192 | MEDIUM | 5.5 | — | Sep 22, 2026 | InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-s... |
| CVE-2026-75656 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | Bridge is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker... |
| CVE-2026-75638 | MEDIUM | 6.5 | 1.3% | Sep 22, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur... |
| CVE-2026-75634 | MEDIUM | 4.3 | — | Sep 22, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur... |
| CVE-2026-75633 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de... |
| CVE-2026-63386 | MEDIUM | 5.3 | 0.5% | Sep 22, 2026 | js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in the recurs... |
| CVE-2026-48361 | MEDIUM | 6.1 | 0.2% | Sep 22, 2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to in... |
| CVE-2026-37603 | MEDIUM | 6.5 | 0.4% | Sep 22, 2026 | Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Soc... |
| CVE-2026-95660 | MEDIUM | 6.3 | — | Sep 22, 2026 | A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function o... |
| CVE-2026-95624 | MEDIUM | 6.8 | — | Sep 22, 2026 | The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaS... |
| CVE-2026-86056 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/... |
| CVE-2026-85288 | MEDIUM | 6.7 | 0.1% | Sep 22, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HM... |
| CVE-2026-77270 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th... |
| CVE-2026-77265 | MEDIUM | 5.9 | 0.4% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, he... |
| CVE-2026-77252 | MEDIUM | 6.5 | 0.4% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ca... |
| CVE-2026-77250 | MEDIUM | 6.1 | 0.1% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OA... |
| CVE-2026-18626 | MEDIUM | 6.8 | — | Sep 22, 2026 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affect... |
| CVE-2026-18460 | MEDIUM | 6.9 | — | Sep 22, 2026 | Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers... |
| CVE-2026-18458 | MEDIUM | 6.8 | — | Sep 22, 2026 | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type ... |
| CVE-2026-11389 | MEDIUM | 6.8 | — | Sep 22, 2026 | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now