2026 CVE Vulnerabilities

50,996 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-67309HIGH7.8Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider...
CVE-2026-67308CRITICAL9.3Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execut...
CVE-2026-67307HIGH7Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inven...
CVE-2026-67306MEDIUM5.4FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fu...
CVE-2026-67305CRITICAL9.4FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when...
CVE-2026-67304HIGH8.7FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when...
CVE-2026-67303MEDIUM5.3FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_proce...
CVE-2026-67302MEDIUM5.3FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redire...
CVE-2026-67301HIGH8.7FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC an...
CVE-2026-67300HIGH8.7FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAI...
CVE-2026-67299HIGH8.7FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER...
CVE-2026-67298HIGH8.7FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_...
CVE-2026-67297HIGH8.7FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses...
CVE-2026-67296HIGH8.7FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid...
CVE-2026-67295MEDIUM6.3FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to...
CVE-2026-67294CRITICAL9.3FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si...
CVE-2026-67293CRITICAL9.3FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. ...
CVE-2026-67292CRITICAL9.3FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor...
CVE-2026-67291HIGH8.7FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments...
CVE-2026-67290HIGH8.7FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG...
CVE-2026-67289CRITICAL9.8FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controll...
CVE-2026-67288HIGH8.7FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept ...
CVE-2026-66402CRITICAL9.8FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in ...
CVE-2026-66401LOW2.4FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail...
CVE-2026-2411MEDIUM6.5Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now