2026 CVE Vulnerabilities

50,985 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8763CRITICAL9.3In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also a...
CVE-2026-65875HIGH7.1BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens...
CVE-2026-59652MEDIUM6.9In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
CVE-2026-59651HIGH7.1In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue als...
CVE-2026-59650CRITICAL9.3In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects...
CVE-2026-59649HIGH8.7In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issu...
CVE-2026-59648MEDIUM5.3In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also aff...
CVE-2026-59647MEDIUM5.3In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects ...
CVE-2026-59646HIGH7.5In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This is...
CVE-2026-59645HIGH7.5In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. T...
CVE-2026-59644HIGH8.7In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.
CVE-2026-59643HIGH8.7In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affect...
CVE-2026-59642HIGH7.5In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue...
CVE-2026-59641MEDIUM5.3In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This iss...
CVE-2026-59640MEDIUM5.3In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue ...
CVE-2026-59639HIGH7.5In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue al...
CVE-2026-59638MEDIUM6.5In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. ...
CVE-2026-18581LOW3.3A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of th...
CVE-2026-15055HIGH8.2In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also a...
CVE-2026-12185HIGH8.6In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i...
CVE-2026-3245HIGH7.7A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
CVE-2026-18577HIGH8.1An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu...
CVE-2026-10848HIGH8.6The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j...
CVE-2026-9856HIGH7.1A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes vi...
CVE-2026-65321CRITICAL9.8PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrar...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now