2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71801 | CRITICAL | 9.8 | 0.2% | Sep 9, 2026 | An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token sec... |
| CVE-2026-36433 | CRITICAL | 9.8 | 0.2% | Sep 9, 2026 | An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker exe... |
| CVE-2026-87911 | CRITICAL | 9.6 | 1.0% | Sep 9, 2026 | An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres... |
| CVE-2026-54694 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a s... |
| CVE-2026-87929 | CRITICAL | 9.8 | 0.3% | Sep 9, 2026 | MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never c... |
| CVE-2026-47156 | CRITICAL | 9.3 | 0.5% | Sep 9, 2026 | MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP... |
| CVE-2026-79689 | CRITICAL | 9.8 | 1.9% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-68484 | CRITICAL | 9 | — | Sep 9, 2026 | Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do... |
| CVE-2026-67403 | CRITICAL | 9 | — | Sep 9, 2026 | Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level a... |
| CVE-2026-67401 | CRITICAL | 9.9 | — | Sep 9, 2026 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTr... |
| CVE-2026-22590 | CRITICAL | 9.1 | — | Sep 9, 2026 | eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management ... |
| CVE-2026-79941 | CRITICAL | 9.8 | 1.9% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-86751 | CRITICAL | 9.6 | 0.2% | Sep 9, 2026 | Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to r... |
| CVE-2026-85103 | CRITICAL | 9.8 | — | Sep 9, 2026 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute a... |
| CVE-2026-85102 | CRITICAL | 9.8 | 0.7% | Sep 9, 2026 | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauth... |
| CVE-2026-80172 | CRITICAL | 9.8 | 0.3% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-87827 | CRITICAL | 10 | — | Sep 9, 2026 | Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfac... |
| CVE-2026-85978 | CRITICAL | 9.8 | — | Sep 9, 2026 | An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A pat... |
| CVE-2026-56207 | CRITICAL | 9.8 | 0.2% | Sep 9, 2026 | Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing... |
| CVE-2026-41871 | CRITICAL | 9.8 | 0.4% | Sep 9, 2026 | Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability ... |
| CVE-2026-41869 | CRITICAL | 9.1 | 0.2% | Sep 9, 2026 | Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST... |
| CVE-2026-79696 | CRITICAL | 10 | 0.4% | Sep 9, 2026 | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through ... |
| CVE-2026-16272 | CRITICAL | 9.1 | 0.1% | Sep 9, 2026 | Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame... |
| CVE-2026-21096 | CRITICAL | 9.8 | 0.4% | Sep 9, 2026 | Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attac... |
| CVE-2026-21095 | CRITICAL | 9.8 | 0.4% | Sep 9, 2026 | Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attack... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now