2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54047 | CRITICAL | 9.2 | — | Sep 11, 2026 | Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior t... |
| CVE-2026-3869 | CRITICAL | 9.2 | 0.5% | Sep 11, 2026 | CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentia... |
| CVE-2026-89010 | CRITICAL | 9.8 | — | Sep 11, 2026 | WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command inject... |
| CVE-2026-89009 | CRITICAL | 9.1 | 0.7% | Sep 11, 2026 | WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file wr... |
| CVE-2026-87988 | CRITICAL | 10 | — | Sep 11, 2026 | An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through comma... |
| CVE-2026-87987 | CRITICAL | 10 | — | Sep 11, 2026 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using e... |
| CVE-2026-87986 | CRITICAL | 10 | — | Sep 11, 2026 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using s... |
| CVE-2026-87985 | CRITICAL | 10 | — | Sep 11, 2026 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using A... |
| CVE-2026-87984 | CRITICAL | 9.3 | — | Sep 11, 2026 | An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or over... |
| CVE-2026-87983 | CRITICAL | 9.2 | — | Sep 11, 2026 | An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspac... |
| CVE-2026-71644 | CRITICAL | 9.8 | 0.4% | Sep 11, 2026 | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacke... |
| CVE-2026-84390 | CRITICAL | 9.8 | — | Sep 11, 2026 | A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, F... |
| CVE-2026-80462 | CRITICAL | 10 | 0.3% | Sep 11, 2026 | A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain... |
| CVE-2026-89259 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS ... |
| CVE-2026-86793 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configure... |
| CVE-2026-47839 | CRITICAL | 9.2 | 0.3% | Sep 11, 2026 | A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite oper... |
| CVE-2026-14563 | CRITICAL | 9.8 | 0.1% | Sep 11, 2026 | The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authentica... |
| CVE-2026-14560 | CRITICAL | 10 | 0.2% | Sep 11, 2026 | The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a cl... |
| CVE-2026-14559 | CRITICAL | 9.8 | 0.1% | Sep 11, 2026 | The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating th... |
| CVE-2026-8778 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnera... |
| CVE-2026-82107 | CRITICAL | 9.6 | 0.4% | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ... |
| CVE-2026-81204 | CRITICAL | 9.8 | 0.6% | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection duri... |
| CVE-2026-80424 | CRITICAL | 9.1 | 0.4% | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to... |
| CVE-2026-79724 | CRITICAL | 9.8 | 0.5% | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neu... |
| CVE-2026-78573 | CRITICAL | 9.8 | 0.4% | Sep 10, 2026 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now