2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26084 | CRITICAL | 9.9 | — | Sep 8, 2026 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, ... |
| CVE-2026-86840 | CRITICAL | 9.1 | 0.1% | Sep 8, 2026 | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission... |
| CVE-2026-79574 | CRITICAL | 9.8 | 0.2% | Sep 8, 2026 | An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcas... |
| CVE-2026-79577 | CRITICAL | 9.8 | 0.1% | Sep 8, 2026 | An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without ... |
| CVE-2026-79576 | CRITICAL | 9.8 | 0.3% | Sep 8, 2026 | An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any ... |
| CVE-2026-79571 | CRITICAL | 9.1 | 0.2% | Sep 8, 2026 | Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated atta... |
| CVE-2026-61516 | CRITICAL | 9.8 | 0.4% | Sep 8, 2026 | Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthentica... |
| CVE-2026-12745 | CRITICAL | 9.8 | 2.1% | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticat... |
| CVE-2026-12744 | CRITICAL | 9.8 | 2.2% | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticat... |
| CVE-2026-73309 | CRITICAL | 9.1 | 0.5% | Sep 8, 2026 | XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthent... |
| CVE-2026-77098 | CRITICAL | 9.8 | 0.2% | Sep 8, 2026 | Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to... |
| CVE-2026-77092 | CRITICAL | 9.8 | 0.2% | Sep 8, 2026 | Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers... |
| CVE-2026-77089 | CRITICAL | 9.8 | 0.3% | Sep 8, 2026 | Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade t... |
| CVE-2026-78234 | CRITICAL | 9.9 | — | Sep 8, 2026 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-... |
| CVE-2026-71377 | CRITICAL | 9.8 | — | Sep 8, 2026 | Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Con... |
| CVE-2026-71376 | CRITICAL | 9.8 | — | Sep 8, 2026 | OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container... |
| CVE-2026-62645 | CRITICAL | 9.8 | 0.3% | Sep 8, 2026 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web inte... |
| CVE-2026-50093 | CRITICAL | 9 | 0.2% | Sep 8, 2026 | A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control P... |
| CVE-2026-71374 | CRITICAL | 9.8 | — | Sep 8, 2026 | Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Compon... |
| CVE-2026-86510 | CRITICAL | 9.9 | 0.5% | Sep 8, 2026 | A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2T... |
| CVE-2026-86509 | CRITICAL | 9.6 | 0.4% | Sep 8, 2026 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serv... |
| CVE-2026-76969 | CRITICAL | 9.4 | 0.3% | Sep 8, 2026 | @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applicatio... |
| CVE-2026-66768 | CRITICAL | 9 | 0.3% | Sep 8, 2026 | SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backen... |
| CVE-2026-58240 | CRITICAL | 9.8 | 0.3% | Sep 8, 2026 | SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components d... |
| CVE-2026-44756 | CRITICAL | 10 | 0.3% | Sep 8, 2026 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now