2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-87500CRITICAL9.6Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potenti...
CVE-2026-87494CRITICAL9.6Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging soc...
CVE-2026-87492CRITICAL9.6Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially exe...
CVE-2026-87488CRITICAL9.6Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbit...
CVE-2026-87474CRITICAL9.6Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbi...
CVE-2026-87470CRITICAL9.6Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to pote...
CVE-2026-87464CRITICAL9.6Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outs...
CVE-2026-87455CRITICAL9.6Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrar...
CVE-2026-87448CRITICAL9.6Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code o...
CVE-2026-87438CRITICAL9.6Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute ...
CVE-2026-53939CRITICAL9.1OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through...
CVE-2026-53581CRITICAL9OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 ...
CVE-2026-85982CRITICAL9The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of d...
CVE-2026-86464CRITICAL9.9In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity...
CVE-2026-84869CRITICAL9.9A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session ...
CVE-2026-84197CRITICAL9.2In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from ...
CVE-2026-78623CRITICAL9.9The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the a...
CVE-2026-75746CRITICAL9.1ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulner...
CVE-2026-48273CRITICAL9.9ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vuln...
CVE-2026-19232CRITICAL9.9Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code exe...
CVE-2026-82004CRITICAL10Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co...
CVE-2026-76201CRITICAL9.3Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to i...
CVE-2026-76200CRITICAL9.3Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to i...
CVE-2026-66302CRITICAL9.8External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a netwo...
CVE-2026-58822CRITICAL9.8In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now