2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20271 | HIGH | 8.6 | 0.3% | Aug 5, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t... |
| CVE-2026-20270 | HIGH | 8.6 | 0.3% | Aug 5, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t... |
| CVE-2026-20269 | HIGH | 8.6 | 0.3% | Aug 5, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t... |
| CVE-2026-20268 | HIGH | 8.6 | 0.3% | Aug 5, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t... |
| CVE-2026-20263 | HIGH | 8.6 | 0.3% | Aug 5, 2026 | A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauth... |
| CVE-2026-20200 | HIGH | 8.8 | 0.8% | Aug 5, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with lo... |
| CVE-2026-20124 | HIGH | 7.7 | 0.3% | Aug 5, 2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe... |
| CVE-2026-17630 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation... |
| CVE-2026-17626 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitiv... |
| CVE-2026-17623 | HIGH | 8.8 | 0.9% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to i... |
| CVE-2026-9203 | HIGH | 8.5 | 0.2% | Aug 5, 2026 | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate... |
| CVE-2026-7327 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server... |
| CVE-2026-7326 | HIGH | 7.5 | 0.1% | Aug 5, 2026 | A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows ... |
| CVE-2026-70604 | HIGH | 7.4 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10... |
| CVE-2026-70601 | HIGH | 7.5 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,... |
| CVE-2026-60023 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An... |
| CVE-2026-48911 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: throug... |
| CVE-2026-48834 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: t... |
| CVE-2026-15572 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mappe... |
| CVE-2026-13477 | HIGH | 8.8 | 0.2% | Aug 5, 2026 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege... |
| CVE-2026-54876 | HIGH | 7.5 | — | Aug 5, 2026 | Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by... |
| CVE-2026-17613 | HIGH | 7.5 | — | Aug 5, 2026 | Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated ... |
| CVE-2026-16102 | HIGH | 8.1 | 0.3% | Aug 5, 2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solut... |
| CVE-2026-15573 | HIGH | 8.1 | 0.3% | Aug 5, 2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security ... |
| CVE-2026-12410 | HIGH | 7.8 | — | Aug 5, 2026 | Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now