2026 CVE Vulnerabilities

50,066 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39924MEDIUM6.8Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess...
CVE-2026-39923CRITICAL9.2Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers t...
CVE-2026-32835Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18531MEDIUM5.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use ...
CVE-2026-16442CRITICAL9.8A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authenti...
CVE-2026-15656MEDIUM4.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook...
CVE-2026-15587CRITICAL9.4Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows...
CVE-2026-15572HIGH8.8A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mappe...
CVE-2026-13477HIGH8.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege...
CVE-2026-12762MEDIUM5.3IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti...
CVE-2026-12730LOW3.8IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug...
CVE-2026-10025CRITICAL9.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injec...
CVE-2026-54876HIGH7.5Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by...
CVE-2026-17613HIGH7.5Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated ...
CVE-2026-16102HIGH8.1A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solut...
CVE-2026-16100MEDIUM6.5A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error...
CVE-2026-16071MEDIUM5.4A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc...
CVE-2026-15573HIGH8.1A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security ...
CVE-2026-12410HIGH7.8Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-...
CVE-2026-7529HIGH7.5The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and...
CVE-2026-7456MEDIUM6.5The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2026-67623HIGH8.8Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com...
CVE-2026-17506HIGH7.2The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr...
CVE-2026-16443CRITICAL9.1A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine ...
CVE-2026-15979HIGH8.1The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Del...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now