2026 CVE Vulnerabilities

65,524 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-101056MEDIUM5.3Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID....
CVE-2026-101051LOW3.1Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated use...
CVE-2026-101048MEDIUM5.4Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/...
CVE-2026-101047MEDIUM5.3Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enter...
CVE-2026-101046LOW3.1Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities...
CVE-2026-101045HIGH8Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests gen...
CVE-2026-101044HIGH7.1pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha....
CVE-2026-101043HIGH7.4pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the htt...
CVE-2026-88778HIGH7.5Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This i...
CVE-2026-88777CRITICAL9.8Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects AD...
CVE-2026-88776CRITICAL9.8Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC...
CVE-2026-88775CRITICAL9.8Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1...
CVE-2026-88774HIGH7.2Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 1...
CVE-2026-88773CRITICAL10Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC a...
CVE-2026-88772HIGH8.1Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 1...
CVE-2026-88771CRITICAL9.8Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: b...
CVE-2026-101050MEDIUM6.5Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credent...
CVE-2026-101049MEDIUM6.5Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing...
CVE-2026-101042MEDIUM6.4Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-ba...
CVE-2026-101041MEDIUM6.3The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check...
CVE-2026-101033MEDIUM4.3KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operati...
CVE-2026-101032HIGH7navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Atta...
CVE-2026-100872HIGH7.5Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthentic...
CVE-2026-100871HIGH8.8Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT token...
CVE-2026-100870HIGH8.8Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the r...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now