2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77243 | HIGH | 8.8 | 0.5% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, EN... |
| CVE-2026-77242 | HIGH | 7.5 | 0.3% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, va... |
| CVE-2026-43643 | HIGH | 7.5 | — | Sep 22, 2026 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing m... |
| CVE-2026-43642 | HIGH | 8.1 | 1.0% | Sep 22, 2026 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing mo... |
| CVE-2026-18462 | HIGH | 7.3 | — | Sep 22, 2026 | Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allow... |
| CVE-2026-18459 | HIGH | 8.7 | — | Sep 22, 2026 | Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. Th... |
| CVE-2026-18457 | HIGH | 8.3 | — | Sep 22, 2026 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issu... |
| CVE-2026-94455 | HIGH | 7.1 | — | Sep 22, 2026 | An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The a... |
| CVE-2026-87902 | HIGH | 8.1 | 2.9% | Sep 22, 2026 | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph... |
| CVE-2026-85740 | HIGH | 7.1 | — | Sep 22, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parse... |
| CVE-2026-83803 | HIGH | 7.7 | 0.6% | Sep 22, 2026 | Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the reloca... |
| CVE-2026-83603 | HIGH | 8.4 | 0.3% | Sep 22, 2026 | Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-sta... |
| CVE-2026-83599 | HIGH | 7.5 | 0.7% | Sep 22, 2026 | Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates per... |
| CVE-2026-83598 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powe... |
| CVE-2026-13087 | HIGH | 8.8 | — | Sep 22, 2026 | A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/x... |
| CVE-2026-95806 | HIGH | 7.7 | — | Sep 22, 2026 | MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar... |
| CVE-2026-95655 | HIGH | 8.1 | 0.5% | Sep 22, 2026 | Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated use... |
| CVE-2026-95654 | HIGH | 7.4 | 0.5% | Sep 22, 2026 | Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization de... |
| CVE-2026-95653 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead... |
| CVE-2026-94640 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (... |
| CVE-2026-85055 | HIGH | 7.1 | 0.4% | Sep 22, 2026 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission i... |
| CVE-2026-80150 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, ... |
| CVE-2026-80149 | HIGH | 8.6 | 0.6% | Sep 22, 2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, ... |
| CVE-2026-80148 | HIGH | 8.6 | 0.6% | Sep 22, 2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, ... |
| CVE-2026-77633 | HIGH | 7.1 | 0.4% | Sep 22, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now