2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11388 | MEDIUM | 6.9 | — | Sep 22, 2026 | Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Conn... |
| CVE-2026-86062 | MEDIUM | 6.1 | — | Sep 22, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieva... |
| CVE-2026-85725 | MEDIUM | 5.9 | 0.4% | Sep 22, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwo... |
| CVE-2026-85709 | MEDIUM | 5.3 | — | Sep 22, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Py... |
| CVE-2026-84301 | MEDIUM | 6.3 | 0.4% | Sep 22, 2026 | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios... |
| CVE-2026-83602 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api... |
| CVE-2026-83601 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENS... |
| CVE-2026-83600 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART ... |
| CVE-2026-76805 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path ... |
| CVE-2026-76804 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loadi... |
| CVE-2026-76803 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript... |
| CVE-2026-76802 | MEDIUM | 4.7 | 0.2% | Sep 22, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading b... |
| CVE-2026-56682 | MEDIUM | 5.3 | — | Sep 22, 2026 | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without ... |
| CVE-2026-95805 | MEDIUM | 5.3 | — | Sep 22, 2026 | A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action t... |
| CVE-2026-90462 | MEDIUM | 5.4 | — | Sep 22, 2026 | A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `... |
| CVE-2026-88010 | MEDIUM | 6.3 | 0.7% | Sep 22, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewar... |
| CVE-2026-86805 | MEDIUM | 6.3 | — | Sep 22, 2026 | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versio... |
| CVE-2026-81886 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit ... |
| CVE-2026-81885 | MEDIUM | 5.5 | 0.1% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation f... |
| CVE-2026-81882 | MEDIUM | 6.1 | 0.1% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property... |
| CVE-2026-81881 | MEDIUM | 4.4 | 0.1% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift fi... |
| CVE-2026-81880 | MEDIUM | 5.5 | 0.1% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred... |
| CVE-2026-81879 | MEDIUM | 6.1 | 0.2% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM han... |
| CVE-2026-81878 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecod... |
| CVE-2026-79913 | MEDIUM | 6.5 | — | Sep 22, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side requ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now