2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64257 | CRITICAL | 9.1 | 0.7% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 ... |
| CVE-2026-16766 | CRITICAL | 9.8 | 1.3% | Jul 25, 2026 | Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. ... |
| CVE-2026-16280 | CRITICAL | 9.8 | 0.3% | Jul 24, 2026 | An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computa... |
| CVE-2026-61884 | CRITICAL | 9.8 | 0.7% | Jul 24, 2026 | The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credential... |
| CVE-2026-48021 | CRITICAL | 9.1 | 0.1% | Jul 24, 2026 | In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA ba... |
| CVE-2026-64232 | CRITICAL | 9.8 | 0.5% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_inser... |
| CVE-2026-64216 | CRITICAL | 9.8 | 0.4% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_... |
| CVE-2026-58630 | CRITICAL | 9.8 | 0.8% | Jul 24, 2026 | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-58586 | CRITICAL | 9.8 | 0.4% | Jul 24, 2026 | Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the sys... |
| CVE-2026-57106 | CRITICAL | 10 | 0.9% | Jul 24, 2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-56163 | CRITICAL | 10 | 0.9% | Jul 24, 2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el... |
| CVE-2026-12503 | CRITICAL | 9.2 | 0.1% | Jul 24, 2026 | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-... |
| CVE-2026-16634 | CRITICAL | 9.8 | 0.2% | Jul 24, 2026 | TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is ... |
| CVE-2026-24727 | CRITICAL | 9.3 | 0.7% | Jul 24, 2026 | An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporat... |
| CVE-2026-15704 | CRITICAL | 9.8 | 0.4% | Jul 24, 2026 | In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authori... |
| CVE-2026-12877 | CRITICAL | 9.1 | 0.1% | Jul 24, 2026 | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user s... |
| CVE-2026-62825 | CRITICAL | 9.8 | 0.7% | Jul 24, 2026 | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-58275 | CRITICAL | 9.8 | 0.7% | Jul 24, 2026 | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-56191 | CRITICAL | 10 | 0.7% | Jul 24, 2026 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network... |
| CVE-2026-56165 | CRITICAL | 9.8 | 0.7% | Jul 24, 2026 | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. |
| CVE-2026-56160 | CRITICAL | 9.9 | 0.7% | Jul 24, 2026 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a netwo... |
| CVE-2026-50517 | CRITICAL | 9.9 | 1.3% | Jul 24, 2026 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. |
| CVE-2026-42933 | CRITICAL | 10 | 0.3% | Jul 23, 2026 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow ... |
| CVE-2026-28698 | CRITICAL | 9.2 | 0.3% | Jul 23, 2026 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr... |
| CVE-2026-63732 | CRITICAL | 9.9 | 0.7% | Jul 23, 2026 | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authent... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now