2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-64257CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 ...
CVE-2026-16766CRITICAL9.8Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. ...
CVE-2026-16280CRITICAL9.8An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computa...
CVE-2026-61884CRITICAL9.8The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credential...
CVE-2026-48021CRITICAL9.1In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA ba...
CVE-2026-64232CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_inser...
CVE-2026-64216CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_...
CVE-2026-58630CRITICAL9.8Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58586CRITICAL9.8Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the sys...
CVE-2026-57106CRITICAL10Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56163CRITICAL10Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el...
CVE-2026-12503CRITICAL9.2Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-...
CVE-2026-16634CRITICAL9.8TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is ...
CVE-2026-24727CRITICAL9.3An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporat...
CVE-2026-15704CRITICAL9.8In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authori...
CVE-2026-12877CRITICAL9.1The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user s...
CVE-2026-62825CRITICAL9.8Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58275CRITICAL9.8Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56191CRITICAL10Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network...
CVE-2026-56165CRITICAL9.8Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-56160CRITICAL9.9Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a netwo...
CVE-2026-50517CRITICAL9.9Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-42933CRITICAL10Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow ...
CVE-2026-28698CRITICAL9.2Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr...
CVE-2026-63732CRITICAL9.99router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authent...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now