2026 CVE Vulnerabilities
49,109 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7888 | HIGH | 8.4 | 0.2% | Jun 3, 2026 | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and ... |
| CVE-2026-46273 | HIGH | 8.6 | 0.4% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS So... |
| CVE-2026-46271 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link ... |
| CVE-2026-46270 | HIGH | 8.4 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_... |
| CVE-2026-46267 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freein... |
| CVE-2026-46265 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc i... |
| CVE-2026-46264 | HIGH | 8.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of dev... |
| CVE-2026-46263 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds stream encoder i... |
| CVE-2026-46260 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node()... |
| CVE-2026-46259 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading rea... |
| CVE-2026-46253 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_s... |
| CVE-2026-46251 | HIGH | 8.4 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dirty_list corruption ... |
| CVE-2026-46250 | HIGH | 7.3 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: MIPS: Work around LLVM bug when gp is used as globa... |
| CVE-2026-46246 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for e... |
| CVE-2026-40290 | HIGH | 7.8 | 0.2% | Jun 3, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-36611 | HIGH | 7.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST r... |
| CVE-2026-36609 | HIGH | 7.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change ... |
| CVE-2026-36608 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to ... |
| CVE-2026-36607 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP ... |
| CVE-2026-36606 | HIGH | 7.1 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key ... |
| CVE-2026-36603 | HIGH | 8.1 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication... |
| CVE-2026-20230 | HIGH | 8.6 | 41.7% | Jun 3, 2026 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma... |
| CVE-2026-6657 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation whe... |
| CVE-2026-44281 | HIGH | 7 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0... |
| CVE-2026-42321 | HIGH | 8.4 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now