2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28313 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijackin... |
| CVE-2026-28312 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system adm... |
| CVE-2026-28310 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate the... |
| CVE-2026-28309 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create syst... |
| CVE-2026-28308 | CRITICAL | 9.1 | 0.5% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e... |
| CVE-2026-28307 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated int... |
| CVE-2026-28306 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate thei... |
| CVE-2026-28305 | CRITICAL | 9.1 | 0.5% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e... |
| CVE-2026-28304 | CRITICAL | 9.1 | 0.5% | Jul 21, 2026 | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary exe... |
| CVE-2026-28302 | CRITICAL | 9.1 | 0.6% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc... |
| CVE-2026-65049 | CRITICAL | 9.3 | — | Jul 21, 2026 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability th... |
| CVE-2026-65048 | CRITICAL | 9.3 | — | Jul 21, 2026 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting ... |
| CVE-2026-16412 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruptio... |
| CVE-2026-16411 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2026-16410 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird ... |
| CVE-2026-16408 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153... |
| CVE-2026-16407 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153... |
| CVE-2026-16406 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16402 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16395 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16394 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16393 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunder... |
| CVE-2026-16392 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird ... |
| CVE-2026-16390 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13,... |
| CVE-2026-16389 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firef... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now