2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-28313CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijackin...
CVE-2026-28312CRITICAL9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system adm...
CVE-2026-28310CRITICAL9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate the...
CVE-2026-28309CRITICAL9.1SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create syst...
CVE-2026-28308CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e...
CVE-2026-28307CRITICAL9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated int...
CVE-2026-28306CRITICAL9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate thei...
CVE-2026-28305CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e...
CVE-2026-28304CRITICAL9.1SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary exe...
CVE-2026-28302CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc...
CVE-2026-65049CRITICAL9.3Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability th...
CVE-2026-65048CRITICAL9.3Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting ...
CVE-2026-16412CRITICAL9.8Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruptio...
CVE-2026-16411CRITICAL9.8Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2026-16410CRITICAL9.8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird ...
CVE-2026-16408CRITICAL9.8Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153...
CVE-2026-16407CRITICAL9.8Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153...
CVE-2026-16406CRITICAL9.1Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16402CRITICAL9.8Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16395CRITICAL9.8Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16394CRITICAL9.1Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16393CRITICAL9.1Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunder...
CVE-2026-16392CRITICAL9.1JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird ...
CVE-2026-16390CRITICAL9.1Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13,...
CVE-2026-16389CRITICAL9.8Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firef...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now