2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21095 | CRITICAL | 9.8 | 0.4% | Sep 9, 2026 | Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attack... |
| CVE-2026-87654 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbi... |
| CVE-2026-87650 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arb... |
| CVE-2026-87646 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitr... |
| CVE-2026-87643 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially e... |
| CVE-2026-87638 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute ar... |
| CVE-2026-87637 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbi... |
| CVE-2026-87634 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute ... |
| CVE-2026-87621 | CRITICAL | 9.6 | 0.2% | Sep 9, 2026 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentia... |
| CVE-2026-87613 | CRITICAL | 9 | 0.2% | Sep 9, 2026 | Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potent... |
| CVE-2026-87609 | CRITICAL | 9.6 | 0.2% | Sep 9, 2026 | Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitra... |
| CVE-2026-87607 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially exec... |
| CVE-2026-87595 | CRITICAL | 9.8 | 0.2% | Sep 9, 2026 | Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging socia... |
| CVE-2026-87581 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineeri... |
| CVE-2026-87558 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitr... |
| CVE-2026-87547 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveragin... |
| CVE-2026-87544 | CRITICAL | 9.8 | 0.3% | Sep 9, 2026 | Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system... |
| CVE-2026-87534 | CRITICAL | 9.8 | 0.2% | Sep 9, 2026 | Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leverag... |
| CVE-2026-87529 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execu... |
| CVE-2026-87528 | CRITICAL | 9.6 | 0.2% | Sep 9, 2026 | Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially ex... |
| CVE-2026-87527 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code out... |
| CVE-2026-87526 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineer... |
| CVE-2026-87520 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitr... |
| CVE-2026-87512 | CRITICAL | 9.6 | 0.4% | Sep 9, 2026 | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbit... |
| CVE-2026-87504 | CRITICAL | 9.6 | 0.2% | Sep 9, 2026 | Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now