2026 CVE Vulnerabilities
64,705 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87899 | CRITICAL | 9.4 | 0.5% | Sep 23, 2026 | Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root pr... |
| CVE-2026-87898 | CRITICAL | 9.4 | 0.9% | Sep 23, 2026 | OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges. |
| CVE-2026-84719 | CRITICAL | 9.9 | 0.4% | Sep 23, 2026 | A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the dee... |
| CVE-2026-75884 | CRITICAL | 9.1 | 0.4% | Sep 23, 2026 | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts au... |
| CVE-2026-96770 | CRITICAL | 9.3 | 0.3% | Sep 23, 2026 | All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use ... |
| CVE-2026-95601 | CRITICAL | 9.3 | — | Sep 23, 2026 | Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. |
| CVE-2026-84502 | CRITICAL | 9.9 | — | Sep 23, 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not valid... |
| CVE-2026-84474 | CRITICAL | 9.9 | — | Sep 23, 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host... |
| CVE-2026-77602 | CRITICAL | 9.9 | — | Sep 23, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-63132 | CRITICAL | 9.2 | — | Sep 23, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path... |
| CVE-2026-86934 | CRITICAL | 9.1 | 0.1% | Sep 23, 2026 | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an exten... |
| CVE-2026-86930 | CRITICAL | 9.1 | 0.1% | Sep 23, 2026 | An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted imag... |
| CVE-2026-96759 | CRITICAL | 9.8 | — | Sep 23, 2026 | orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator opt... |
| CVE-2026-96758 | CRITICAL | 9.8 | — | Sep 23, 2026 | orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape... |
| CVE-2026-96757 | CRITICAL | 9.8 | — | Sep 23, 2026 | orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string li... |
| CVE-2026-96755 | CRITICAL | 9.8 | — | Sep 23, 2026 | orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts... |
| CVE-2026-96754 | CRITICAL | 9.8 | 0.4% | Sep 23, 2026 | orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape Op... |
| CVE-2026-95848 | CRITICAL | 9.3 | — | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class canno... |
| CVE-2026-85724 | CRITICAL | 9.6 | 0.3% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, Authorizations... |
| CVE-2026-18872 | CRITICAL | 9.3 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in th... |
| CVE-2026-96276 | CRITICAL | 9.8 | — | Sep 23, 2026 | If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak ... |
| CVE-2026-96560 | CRITICAL | 9.8 | — | Sep 23, 2026 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_t... |
| CVE-2026-86708 | CRITICAL | 10 | — | Sep 23, 2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud servi... |
| CVE-2026-59167 | CRITICAL | 10 | 0.4% | Sep 23, 2026 | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the... |
| CVE-2026-86246 | CRITICAL | 9.1 | — | Sep 23, 2026 | Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now