2026 CVE Vulnerabilities

48,529 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-59118CRITICAL9.3Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-59115CRITICAL9.9'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges ove...
CVE-2026-56162CRITICAL10Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56161CRITICAL9.6Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVE-2026-50515CRITICAL9.9Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVE-2026-50481CRITICAL9.9Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privile...
CVE-2026-49163HIGH8.8Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a...
CVE-2026-17264MEDIUM5.3Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of...
CVE-2026-15805Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8325HIGH7.8A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A ma...
CVE-2026-7867HIGH7.8A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization chec...
CVE-2026-7406HIGH7.8A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference...
CVE-2026-7405MEDIUM5.5A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-B...
CVE-2026-71555MEDIUM4.1PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS do...
CVE-2026-71554MEDIUM5.3h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header ...
CVE-2026-71498MEDIUM5.1node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final byt...
CVE-2026-71497MEDIUM4.7jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectl...
CVE-2026-71488HIGH7.5league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially craf...
CVE-2026-71478MEDIUM6.1league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the Attributes...
CVE-2026-71476HIGH8.7Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx sel...
CVE-2026-71447MEDIUM6.9AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages...
CVE-2026-71446MEDIUM6.9AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedde...
CVE-2026-71445HIGH8.2AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occu...
CVE-2026-71439MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11....
CVE-2026-71438LOW2.4Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now