2026 CVE Vulnerabilities

49,109 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7888HIGH8.4Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and ...
CVE-2026-46273HIGH8.6In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS So...
CVE-2026-46271HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link ...
CVE-2026-46270HIGH8.4In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_...
CVE-2026-46267HIGH7.8In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freein...
CVE-2026-46265HIGH7.5In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc i...
CVE-2026-46264HIGH8.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of dev...
CVE-2026-46263HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds stream encoder i...
CVE-2026-46260HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node()...
CVE-2026-46259HIGH7.8In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading rea...
CVE-2026-46253HIGH7.8In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_s...
CVE-2026-46251HIGH8.4In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dirty_list corruption ...
CVE-2026-46250HIGH7.3In the Linux kernel, the following vulnerability has been resolved: MIPS: Work around LLVM bug when gp is used as globa...
CVE-2026-46246HIGH7.8In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for e...
CVE-2026-40290HIGH7.8OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-36611HIGH7.3Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST r...
CVE-2026-36609HIGH7.3Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change ...
CVE-2026-36608HIGH8.8Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to ...
CVE-2026-36607HIGH8.8Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP ...
CVE-2026-36606HIGH7.1Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key ...
CVE-2026-36603HIGH8.1Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication...
CVE-2026-20230HIGH8.6A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma...
CVE-2026-6657HIGH8.8A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation whe...
CVE-2026-44281HIGH7GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0...
CVE-2026-42321HIGH8.4GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now