2026 CVE Vulnerabilities

50,971 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56846HIGH7.5A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memor...
CVE-2026-56845HIGH7.5An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configur...
CVE-2026-66326HIGH8.8Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66325MEDIUM6.1Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin...
CVE-2026-66322MEDIUM5.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne...
CVE-2026-66321CRITICAL9.6Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-66318HIGH8.1Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over ...
CVE-2026-66317MEDIUM5.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n...
CVE-2026-66316MEDIUM5.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne...
CVE-2026-66315HIGH7.5Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66314MEDIUM5.3Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to ...
CVE-2026-66313MEDIUM6.8Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-66312HIGH8.8Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-66311MEDIUM6.2Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-66310HIGH7.1External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat...
CVE-2026-65804MEDIUM6.1Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized atta...
CVE-2026-65802HIGH7.4External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat...
CVE-2026-62870HIGH8.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-18686CRITICAL9.8A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of ...
CVE-2026-18685CRITICAL9.8A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the...
CVE-2026-11836LOW1.8Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in...
CVE-2026-11835MEDIUM5.6Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateRese...
CVE-2026-67978HIGH7.5An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmittin...
CVE-2026-67673MEDIUM4.6A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is...
CVE-2026-48399HIGH7.5Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now