2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53940 | HIGH | 8.8 | 0.5% | Sep 21, 2026 | Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior... |
| CVE-2026-36467 | HIGH | 7.2 | 0.5% | Sep 21, 2026 | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticate... |
| CVE-2026-94184 | HIGH | 8.1 | 0.4% | Sep 21, 2026 | A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail ... |
| CVE-2026-80110 | HIGH | 8.1 | 0.1% | Sep 21, 2026 | A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcar... |
| CVE-2026-75939 | HIGH | 7.4 | 0.2% | Sep 21, 2026 | A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signature... |
| CVE-2026-71543 | HIGH | 7.5 | 0.4% | Sep 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies... |
| CVE-2026-68919 | HIGH | 7 | 0.5% | Sep 21, 2026 | GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious mater... |
| CVE-2026-61629 | HIGH | 7.5 | 0.6% | Sep 21, 2026 | nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware ... |
| CVE-2026-61628 | HIGH | 8.1 | 0.4% | Sep 21, 2026 | nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish... |
| CVE-2026-55567 | HIGH | 7.8 | 0.1% | Sep 21, 2026 | BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not ... |
| CVE-2026-55074 | HIGH | 8.2 | 0.4% | Sep 21, 2026 | Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.... |
| CVE-2026-55071 | HIGH | 8.4 | 0.3% | Sep 21, 2026 | MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0... |
| CVE-2026-52741 | HIGH | 7.5 | 0.4% | Sep 21, 2026 | GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from comm... |
| CVE-2026-94404 | HIGH | 7.1 | — | Sep 21, 2026 | MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser ... |
| CVE-2026-94401 | HIGH | 8.3 | — | Sep 21, 2026 | MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access i... |
| CVE-2026-88807 | HIGH | 8.9 | 0.3% | Sep 21, 2026 | A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject cod... |
| CVE-2026-88806 | HIGH | 7.5 | 0.2% | Sep 21, 2026 | A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing th... |
| CVE-2026-94383 | HIGH | 8.6 | — | Sep 21, 2026 | The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file ext... |
| CVE-2026-94381 | HIGH | 8.7 | — | Sep 21, 2026 | MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API... |
| CVE-2026-94374 | HIGH | 8.3 | — | Sep 21, 2026 | MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event mode... |
| CVE-2026-84285 | HIGH | 8.8 | — | Sep 21, 2026 | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker... |
| CVE-2026-94368 | HIGH | 7.1 | 0.1% | Sep 21, 2026 | A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object ... |
| CVE-2026-91866 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work... |
| CVE-2026-91865 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentia... |
| CVE-2026-91864 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into me... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now