2026 CVE Vulnerabilities

68,698 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-59156MEDIUM6.5OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-54148HIGH8.1http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvid...
CVE-2026-54147MEDIUM6.5http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvid...
CVE-2026-1037MEDIUM6.1IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2026-1031MEDIUM6.1IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2026-1030MEDIUM4.3IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error m...
CVE-2026-1029MEDIUM5.4IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2026-1025MEDIUM6.1IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2026-11537MEDIUM4.3IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the fi...
CVE-2026-11381HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to i...
CVE-2026-11378HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a...
CVE-2026-11375HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a...
CVE-2026-10858CRITICAL9.9IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote...
CVE-2026-10853HIGH8.8IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arb...
CVE-2026-10841MEDIUM4.8IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
CVE-2026-10751HIGH7.5IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applicati...
CVE-2026-10747CRITICAL10IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to...
CVE-2026-10744HIGH7.5IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote...
CVE-2026-10575HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a he...
CVE-2026-10030HIGH7.1IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authoriz...
CVE-2026-10027CRITICAL9.8IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow whe...
CVE-2026-93685MEDIUM5.4A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authenti...
CVE-2026-93676LOW3.2xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictio...
CVE-2026-93660MEDIUM6.5SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authe...
CVE-2026-93659HIGH8.1Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now