2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-102495 | — | — | — | Sep 29, 2026 | Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make pars... |
| CVE-2026-86843 | — | — | — | Sep 29, 2026 | The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained... |
| CVE-2026-81930 | — | — | — | Sep 29, 2026 | Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating... |
| CVE-2026-81914 | — | — | — | Sep 29, 2026 | Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly i... |
| CVE-2026-81862 | — | — | — | Sep 29, 2026 | Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperato... |
| CVE-2026-92142 | — | — | — | Sep 29, 2026 | Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC)... |
| CVE-2026-91085 | — | — | — | Sep 29, 2026 | Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command... |
| CVE-2026-91048 | — | — | — | Sep 29, 2026 | The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFact... |
| CVE-2026-91012 | — | — | — | Sep 29, 2026 | org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the c... |
| CVE-2026-91096 | — | — | — | Sep 28, 2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destr... |
| CVE-2026-91095 | — | — | — | Sep 28, 2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::... |
| CVE-2026-84895 | — | — | — | Sep 28, 2026 | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calli... |
| CVE-2026-96760 | — | — | — | Sep 28, 2026 | Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json... |
| CVE-2026-84894 | — | — | — | Sep 28, 2026 | In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a F... |
| CVE-2026-88816 | — | — | — | Sep 28, 2026 | DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref us... |
| CVE-2026-88815 | — | — | — | Sep 28, 2026 | DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to S... |
| CVE-2026-85644 | — | — | — | Sep 28, 2026 | XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS... |
| CVE-2026-58464 | — | — | — | Sep 28, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-58463 | — | — | — | Sep 28, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-91006 | — | — | — | Sep 28, 2026 | Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JV... |
| CVE-2026-90979 | — | — | — | Sep 28, 2026 | LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the ... |
| CVE-2026-100658 | — | — | — | Sep 26, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2026-100657 | — | — | — | Sep 26, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2026-100656 | — | — | — | Sep 26, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2026-100655 | — | — | — | Sep 26, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now