2026 CVE Vulnerabilities

50,562 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16442CRITICAL9.8A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authenti...
CVE-2026-15656MEDIUM4.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook...
CVE-2026-15587CRITICAL9.4Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows...
CVE-2026-15572HIGH8.8A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mappe...
CVE-2026-13477HIGH8.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege...
CVE-2026-12762MEDIUM5.3IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti...
CVE-2026-12730LOW3.8IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug...
CVE-2026-10025CRITICAL9.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injec...
CVE-2026-54876HIGH7.5Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by...
CVE-2026-17613HIGH7.5Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated ...
CVE-2026-16102HIGH8.1A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solut...
CVE-2026-16100MEDIUM6.5A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error...
CVE-2026-16071MEDIUM5.4A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc...
CVE-2026-15573HIGH8.1A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security ...
CVE-2026-12410HIGH7.8Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-...
CVE-2026-7529HIGH7.5The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and...
CVE-2026-7456MEDIUM6.5The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2026-67623HIGH8.8Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com...
CVE-2026-17506HIGH7.2The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr...
CVE-2026-16443CRITICAL9.1A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine ...
CVE-2026-15979HIGH8.1The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Del...
CVE-2026-71294HIGH7.6Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. ...
CVE-2026-71293MEDIUM6.2Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f...
CVE-2026-71292HIGH7.2Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th...
CVE-2026-71291HIGH8.8Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now