2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-85146CRITICAL9.8SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote...
CVE-2026-75754CRITICAL10Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in A...
CVE-2026-67402CRITICAL9.2An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger...
CVE-2026-85440CRITICAL9.8MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling t...
CVE-2026-85438CRITICAL9.8MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and de...
CVE-2026-85437CRITICAL9.8MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust att...
CVE-2026-85435CRITICAL9.1MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allow...
CVE-2026-85434CRITICAL9.1MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. A...
CVE-2026-85433CRITICAL9.8MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to rec...
CVE-2026-85430CRITICAL9.1MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams ...
CVE-2026-85428CRITICAL9.8MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that al...
CVE-2026-85426CRITICAL9.8MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization....
CVE-2026-85425CRITICAL9.8MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes...
CVE-2026-85424CRITICAL9.8MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect wit...
CVE-2026-83711CRITICAL10Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker...
CVE-2026-80098CRITICAL10Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges...
CVE-2026-70352CRITICAL10Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges ...
CVE-2026-65818CRITICAL9.9Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
CVE-2026-62916CRITICAL9.8Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevat...
CVE-2026-85224CRITICAL9.1A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file...
CVE-2026-85223CRITICAL9.9A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /...
CVE-2026-85222CRITICAL9.1A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of...
CVE-2026-85061CRITICAL10MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/do...
CVE-2026-85050CRITICAL9.6Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute ...
CVE-2026-85047CRITICAL9.6Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote at...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now