2026 CVE Vulnerabilities
48,018 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55189 | HIGH | 7.7 | 0.2% | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP fronten... |
| CVE-2026-55188 | HIGH | 8.2 | — | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an a... |
| CVE-2026-53322 | HIGH | 8.8 | 0.2% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling functio... |
| CVE-2026-53303 | HIGH | 7.1 | 0.2% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: protect extension_list reading with sb_lock i... |
| CVE-2026-53300 | HIGH | 7.8 | 0.1% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix NTMP DMA use-after-free issue The ... |
| CVE-2026-53296 | HIGH | 7.8 | 0.2% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: free channels on probe error... |
| CVE-2026-53294 | HIGH | 7.8 | 0.2% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't free the reused channe... |
| CVE-2026-53290 | HIGH | 7.8 | 0.1% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/eustall: Fix drm_dev_put called before strea... |
| CVE-2026-53286 | HIGH | 7.8 | 0.2% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: idpf: fix double free and use-after-free in aux dev... |
| CVE-2026-53284 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: only release the dirty pages io tree after s... |
| CVE-2026-53281 | HIGH | 8.8 | 0.1% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refco... |
| CVE-2026-52784 | HIGH | 8.8 | — | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET... |
| CVE-2026-52783 | HIGH | 8.2 | 0.1% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages mo... |
| CVE-2026-49991 | HIGH | 8.6 | 0.3% | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject pe... |
| CVE-2026-47193 | HIGH | 7.5 | — | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint... |
| CVE-2026-32833 | HIGH | 8.8 | 1.3% | Jun 26, 2026 | Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authe... |
| CVE-2026-47220 | HIGH | 7.5 | 0.7% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38... |
| CVE-2026-13372 | HIGH | 7.2 | 0.3% | Jun 26, 2026 | Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026... |
| CVE-2026-56876 | HIGH | 8.6 | 0.3% | Jun 26, 2026 | extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file contain... |
| CVE-2026-55441 | HIGH | 8.6 | — | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil... |
| CVE-2026-54341 | HIGH | 7.5 | — | Jun 26, 2026 | Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload ... |
| CVE-2026-48743 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,... |
| CVE-2026-48706 | HIGH | 7.5 | 0.6% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9... |
| CVE-2026-48497 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,... |
| CVE-2026-48044 | HIGH | 7.5 | 0.5% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now