2026 CVE Vulnerabilities
48,561 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9754 | HIGH | 7.1 | 0.2% | Jun 9, 2026 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is... |
| CVE-2026-9753 | HIGH | 8.1 | 0.3% | Jun 9, 2026 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed ... |
| CVE-2026-9752 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO... |
| CVE-2026-9750 | HIGH | 7.1 | 0.4% | Jun 9, 2026 | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe... |
| CVE-2026-9749 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran... |
| CVE-2026-9748 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st... |
| CVE-2026-9747 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. |
| CVE-2026-9746 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which... |
| CVE-2026-9743 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines... |
| CVE-2026-9741 | HIGH | 7.1 | 0.1% | Jun 9, 2026 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F... |
| CVE-2026-9740 | HIGH | 8.7 | 0.3% | Jun 9, 2026 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by ... |
| CVE-2026-46374 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers... |
| CVE-2026-46373 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers... |
| CVE-2026-34713 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-34712 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-34711 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparo... |
| CVE-2026-48292 | HIGH | 7.8 | 0.3% | Jun 9, 2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i... |
| CVE-2026-48291 | HIGH | 7.8 | 0.3% | Jun 9, 2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i... |
| CVE-2026-47960 | HIGH | 7.4 | 0.4% | Jun 9, 2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference... |
| CVE-2026-47959 | HIGH | 7.8 | 0.2% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerabili... |
| CVE-2026-47955 | HIGH | 7.8 | 0.2% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could... |
| CVE-2026-47952 | HIGH | 7.8 | 0.2% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer Overflow vulnerabilit... |
| CVE-2026-47937 | HIGH | 7.7 | 0.2% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulne... |
| CVE-2026-47932 | HIGH | 8.8 | 7.8% | Jun 9, 2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir... |
| CVE-2026-47931 | HIGH | 8.4 | 0.6% | Jun 9, 2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could re... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now