2026 CVE Vulnerabilities
50,996 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67309 | HIGH | 7.8 | 0.5% | Aug 1, 2026 | Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider... |
| CVE-2026-67308 | CRITICAL | 9.3 | 0.5% | Aug 1, 2026 | Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execut... |
| CVE-2026-67307 | HIGH | 7 | 0.2% | Aug 1, 2026 | Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inven... |
| CVE-2026-67306 | MEDIUM | 5.4 | 0.3% | Aug 1, 2026 | FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fu... |
| CVE-2026-67305 | CRITICAL | 9.4 | 0.5% | Aug 1, 2026 | FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when... |
| CVE-2026-67304 | HIGH | 8.7 | 0.4% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when... |
| CVE-2026-67303 | MEDIUM | 5.3 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_proce... |
| CVE-2026-67302 | MEDIUM | 5.3 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redire... |
| CVE-2026-67301 | HIGH | 8.7 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC an... |
| CVE-2026-67300 | HIGH | 8.7 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAI... |
| CVE-2026-67299 | HIGH | 8.7 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER... |
| CVE-2026-67298 | HIGH | 8.7 | 0.4% | Aug 1, 2026 | FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_... |
| CVE-2026-67297 | HIGH | 8.7 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses... |
| CVE-2026-67296 | HIGH | 8.7 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid... |
| CVE-2026-67295 | MEDIUM | 6.3 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to... |
| CVE-2026-67294 | CRITICAL | 9.3 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si... |
| CVE-2026-67293 | CRITICAL | 9.3 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. ... |
| CVE-2026-67292 | CRITICAL | 9.3 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor... |
| CVE-2026-67291 | HIGH | 8.7 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments... |
| CVE-2026-67290 | HIGH | 8.7 | 0.4% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG... |
| CVE-2026-67289 | CRITICAL | 9.8 | 0.4% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controll... |
| CVE-2026-67288 | HIGH | 8.7 | 0.4% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept ... |
| CVE-2026-66402 | CRITICAL | 9.8 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in ... |
| CVE-2026-66401 | LOW | 2.4 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail... |
| CVE-2026-2411 | MEDIUM | 6.5 | 0.1% | Aug 1, 2026 | Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now