2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11727 | HIGH | 8.1 | 0.6% | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service... |
| CVE-2026-11726 | HIGH | 8.1 | 0.5% | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or c... |
| CVE-2026-11725 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a... |
| CVE-2026-11716 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote... |
| CVE-2026-93854 | HIGH | 7.2 | 0.2% | Sep 18, 2026 | In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete... |
| CVE-2026-93852 | HIGH | 7.1 | 0.2% | Sep 18, 2026 | In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project with... |
| CVE-2026-75894 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrar... |
| CVE-2026-75893 | HIGH | 7.5 | 0.1% | Sep 18, 2026 | In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg() fun... |
| CVE-2026-93761 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library ma... |
| CVE-2026-93760 | HIGH | 8.2 | 0.5% | Sep 18, 2026 | Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that... |
| CVE-2026-93759 | HIGH | 8.6 | 0.4% | Sep 18, 2026 | Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the d... |
| CVE-2026-93753 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properl... |
| CVE-2026-93752 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to valida... |
| CVE-2026-93749 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attacke... |
| CVE-2026-93748 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-s... |
| CVE-2026-91127 | HIGH | 8.2 | 0.4% | Sep 18, 2026 | File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applic... |
| CVE-2026-85058 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last W... |
| CVE-2026-84975 | HIGH | 7.4 | 0.2% | Sep 18, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuT... |
| CVE-2026-81180 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Profess... |
| CVE-2026-81179 | HIGH | 8.1 | — | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset... |
| CVE-2026-69184 | HIGH | 7.5 | 0.7% | Sep 18, 2026 | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression poi... |
| CVE-2026-63458 | HIGH | 7.1 | 0.3% | Sep 18, 2026 | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenti... |
| CVE-2026-63445 | HIGH | 7.1 | 0.8% | Sep 18, 2026 | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoint... |
| CVE-2026-63199 | HIGH | 8.3 | 0.4% | Sep 18, 2026 | Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the ... |
| CVE-2026-62279 | HIGH | 7.1 | 0.4% | Sep 18, 2026 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an aut... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now