2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-54047CRITICAL9.2Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior t...
CVE-2026-3869CRITICAL9.2CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentia...
CVE-2026-89010CRITICAL9.8WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command inject...
CVE-2026-89009CRITICAL9.1WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file wr...
CVE-2026-87988CRITICAL10An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through comma...
CVE-2026-87987CRITICAL10An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using e...
CVE-2026-87986CRITICAL10An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using s...
CVE-2026-87985CRITICAL10An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using A...
CVE-2026-87984CRITICAL9.3An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or over...
CVE-2026-87983CRITICAL9.2An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspac...
CVE-2026-71644CRITICAL9.8An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacke...
CVE-2026-84390CRITICAL9.8A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, F...
CVE-2026-80462CRITICAL10A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain...
CVE-2026-89259CRITICAL9.8Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS ...
CVE-2026-86793CRITICAL9.8SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configure...
CVE-2026-47839CRITICAL9.2A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite oper...
CVE-2026-14563CRITICAL9.8The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authentica...
CVE-2026-14560CRITICAL10The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a cl...
CVE-2026-14559CRITICAL9.8The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating th...
CVE-2026-8778CRITICAL9.8The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnera...
CVE-2026-82107CRITICAL9.6IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-81204CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection duri...
CVE-2026-80424CRITICAL9.1IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to...
CVE-2026-79724CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neu...
CVE-2026-78573CRITICAL9.8IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now