2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87500 | CRITICAL | 9.6 | 0.2% | Sep 9, 2026 | Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potenti... |
| CVE-2026-87494 | CRITICAL | 9.6 | 0.2% | Sep 9, 2026 | Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging soc... |
| CVE-2026-87492 | CRITICAL | 9.6 | 0.2% | Sep 9, 2026 | Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially exe... |
| CVE-2026-87488 | CRITICAL | 9.6 | 0.4% | Sep 9, 2026 | Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbit... |
| CVE-2026-87474 | CRITICAL | 9.6 | 0.4% | Sep 9, 2026 | Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbi... |
| CVE-2026-87470 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to pote... |
| CVE-2026-87464 | CRITICAL | 9.6 | 0.5% | Sep 9, 2026 | Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outs... |
| CVE-2026-87455 | CRITICAL | 9.6 | 0.3% | Sep 9, 2026 | Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrar... |
| CVE-2026-87448 | CRITICAL | 9.6 | 0.4% | Sep 9, 2026 | Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code o... |
| CVE-2026-87438 | CRITICAL | 9.6 | 0.4% | Sep 9, 2026 | Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute ... |
| CVE-2026-53939 | CRITICAL | 9.1 | 0.2% | Sep 9, 2026 | OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through... |
| CVE-2026-53581 | CRITICAL | 9 | 0.5% | Sep 8, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 ... |
| CVE-2026-85982 | CRITICAL | 9 | 0.2% | Sep 8, 2026 | The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of d... |
| CVE-2026-86464 | CRITICAL | 9.9 | 0.4% | Sep 8, 2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity... |
| CVE-2026-84869 | CRITICAL | 9.9 | 0.4% | Sep 8, 2026 | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session ... |
| CVE-2026-84197 | CRITICAL | 9.2 | 0.2% | Sep 8, 2026 | In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from ... |
| CVE-2026-78623 | CRITICAL | 9.9 | 0.2% | Sep 8, 2026 | The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the a... |
| CVE-2026-75746 | CRITICAL | 9.1 | 1.1% | Sep 8, 2026 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulner... |
| CVE-2026-48273 | CRITICAL | 9.9 | 1.7% | Sep 8, 2026 | ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vuln... |
| CVE-2026-19232 | CRITICAL | 9.9 | 0.6% | Sep 8, 2026 | Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code exe... |
| CVE-2026-82004 | CRITICAL | 10 | 1.4% | Sep 8, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co... |
| CVE-2026-76201 | CRITICAL | 9.3 | — | Sep 8, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to i... |
| CVE-2026-76200 | CRITICAL | 9.3 | — | Sep 8, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to i... |
| CVE-2026-66302 | CRITICAL | 9.8 | 0.5% | Sep 8, 2026 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a netwo... |
| CVE-2026-58822 | CRITICAL | 9.8 | 0.4% | Sep 8, 2026 | In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now