2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-86543CRITICAL9.8knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with...
CVE-2026-86542CRITICAL9.1knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write fi...
CVE-2026-75650CRITICAL10Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability tha...
CVE-2026-86480CRITICAL9.8In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser pri...
CVE-2026-86478CRITICAL9.8In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthent...
CVE-2026-7861CRITICAL9.8Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Manageme...
CVE-2026-18922CRITICAL9.8A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL aux...
CVE-2026-80164CRITICAL9.1Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-80131CRITICAL9.8Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-80129CRITICAL9.8Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-86426CRITICAL9.8LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attac...
CVE-2026-86419CRITICAL9.1Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval an...
CVE-2026-80238CRITICAL9.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-76578CRITICAL9.8A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which ...
CVE-2026-6223CRITICAL9.4Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows A...
CVE-2026-61410CRITICAL9.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-86299CRITICAL9.9A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cg...
CVE-2026-86296CRITICAL10A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhc...
CVE-2026-79698CRITICAL9.9A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6...
CVE-2026-79697CRITICAL9.9A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6...
CVE-2026-16876CRITICAL9.3An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentica...
CVE-2026-86304CRITICAL9.8MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net...
CVE-2026-86219CRITICAL9.8Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified n...
CVE-2026-19931CRITICAL9.8A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, w...
CVE-2026-18924CRITICAL9.1A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with othe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now