2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-26084CRITICAL9.9A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, ...
CVE-2026-86840CRITICAL9.1The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission...
CVE-2026-79574CRITICAL9.8An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcas...
CVE-2026-79577CRITICAL9.8An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without ...
CVE-2026-79576CRITICAL9.8An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any ...
CVE-2026-79571CRITICAL9.1Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated atta...
CVE-2026-61516CRITICAL9.8Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthentica...
CVE-2026-12745CRITICAL9.8A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticat...
CVE-2026-12744CRITICAL9.8A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticat...
CVE-2026-73309CRITICAL9.1XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthent...
CVE-2026-77098CRITICAL9.8Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to...
CVE-2026-77092CRITICAL9.8Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers...
CVE-2026-77089CRITICAL9.8Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade t...
CVE-2026-78234CRITICAL9.9A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-...
CVE-2026-71377CRITICAL9.8Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Con...
CVE-2026-71376CRITICAL9.8OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container...
CVE-2026-62645CRITICAL9.8A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web inte...
CVE-2026-50093CRITICAL9A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control P...
CVE-2026-71374CRITICAL9.8Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Compon...
CVE-2026-86510CRITICAL9.9A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2T...
CVE-2026-86509CRITICAL9.6A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serv...
CVE-2026-76969CRITICAL9.4@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applicatio...
CVE-2026-66768CRITICAL9SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backen...
CVE-2026-58240CRITICAL9.8SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components d...
CVE-2026-44756CRITICAL10A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now