2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71640 | CRITICAL | 9.1 | 0.4% | Sep 10, 2026 | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe... |
| CVE-2026-45764 | CRITICAL | 9.1 | 0.4% | Sep 10, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-19646 | CRITICAL | 9.1 | 0.5% | Sep 10, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote... |
| CVE-2026-89094 | CRITICAL | 9.9 | 0.5% | Sep 10, 2026 | Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files... |
| CVE-2026-85025 | CRITICAL | 9.8 | 0.4% | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and acc... |
| CVE-2026-75940 | CRITICAL | 9.1 | 0.3% | Sep 10, 2026 | A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that c... |
| CVE-2026-89086 | CRITICAL | 9.1 | 0.2% | Sep 10, 2026 | In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decodi... |
| CVE-2026-88062 | CRITICAL | 9.5 | 0.4% | Sep 10, 2026 | OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, ... |
| CVE-2026-89049 | CRITICAL | 9.9 | — | Sep 10, 2026 | A server-side request forgery issue due to improper validation of equivalent address representations in the port forward... |
| CVE-2026-89042 | CRITICAL | 9.1 | 0.3% | Sep 10, 2026 | passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowin... |
| CVE-2026-68006 | CRITICAL | 9.1 | 0.2% | Sep 10, 2026 | An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_... |
| CVE-2026-88044 | CRITICAL | 9.1 | — | Sep 10, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.... |
| CVE-2026-85228 | CRITICAL | 9.1 | — | Sep 10, 2026 | An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36... |
| CVE-2026-68488 | CRITICAL | 9.9 | — | Sep 10, 2026 | A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privileg... |
| CVE-2026-68487 | CRITICAL | 9.9 | — | Sep 10, 2026 | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. |
| CVE-2026-65639 | CRITICAL | 9.5 | — | Sep 10, 2026 | OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who contro... |
| CVE-2026-65638 | CRITICAL | 9.2 | — | Sep 10, 2026 | Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to exe... |
| CVE-2026-52098 | CRITICAL | 9.8 | 0.8% | Sep 10, 2026 | An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoin... |
| CVE-2026-88899 | CRITICAL | 9.8 | 0.4% | Sep 10, 2026 | knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode pro... |
| CVE-2026-88018 | CRITICAL | 9.8 | 0.5% | Sep 10, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-81467 | CRITICAL | 9.8 | 3.8% | Sep 10, 2026 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS C... |
| CVE-2026-81046 | CRITICAL | 9.4 | 0.4% | Sep 10, 2026 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated... |
| CVE-2026-88008 | CRITICAL | 9.1 | 0.4% | Sep 10, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards ... |
| CVE-2026-88007 | CRITICAL | 9.1 | 0.4% | Sep 10, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypo... |
| CVE-2026-81800 | CRITICAL | 9.3 | 0.2% | Sep 10, 2026 | Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now