2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100779 | — | — | — | Sep 29, 2026 | Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42... |
| CVE-2026-100778 | — | — | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.... |
| CVE-2026-100777 | — | — | — | Sep 29, 2026 | Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Fire... |
| CVE-2026-100776 | — | — | — | Sep 29, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157,... |
| CVE-2026-100775 | — | — | — | Sep 29, 2026 | Sandbox escape in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 11... |
| CVE-2026-100774 | — | — | — | Sep 29, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefo... |
| CVE-2026-100773 | — | — | — | Sep 29, 2026 | Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Fire... |
| CVE-2026-100772 | — | — | — | Sep 29, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Fi... |
| CVE-2026-100771 | — | — | — | Sep 29, 2026 | Undefined behavior in the DOM: Streams component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefo... |
| CVE-2026-100770 | — | — | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ES... |
| CVE-2026-100769 | — | — | — | Sep 29, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157,... |
| CVE-2026-100768 | — | — | — | Sep 29, 2026 | Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100767 | — | — | — | Sep 29, 2026 | Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firef... |
| CVE-2026-100766 | — | — | — | Sep 29, 2026 | Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157,... |
| CVE-2026-100765 | — | — | — | Sep 29, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 1... |
| CVE-2026-100763 | — | — | — | Sep 29, 2026 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100762 | — | — | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ES... |
| CVE-2026-100760 | — | — | — | Sep 29, 2026 | Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox ESR 153.4 and Fire... |
| CVE-2026-100759 | — | — | — | Sep 29, 2026 | Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox... |
| CVE-2026-100758 | — | — | — | Sep 29, 2026 | Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox... |
| CVE-2026-100757 | — | — | — | Sep 29, 2026 | Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.... |
| CVE-2026-100756 | — | — | — | Sep 29, 2026 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4,... |
| CVE-2026-66083 | — | — | — | Sep 29, 2026 | The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user c... |
| CVE-2026-102497 | — | — | — | Sep 29, 2026 | The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model grou... |
| CVE-2026-102496 | — | — | — | Sep 29, 2026 | Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a maliciou... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now