2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85146 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote... |
| CVE-2026-75754 | CRITICAL | 10 | 0.2% | Sep 4, 2026 | Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in A... |
| CVE-2026-67402 | CRITICAL | 9.2 | 0.3% | Sep 4, 2026 | An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger... |
| CVE-2026-85440 | CRITICAL | 9.8 | 0.6% | Sep 3, 2026 | MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling t... |
| CVE-2026-85438 | CRITICAL | 9.8 | 0.5% | Sep 3, 2026 | MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and de... |
| CVE-2026-85437 | CRITICAL | 9.8 | 0.7% | Sep 3, 2026 | MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust att... |
| CVE-2026-85435 | CRITICAL | 9.1 | 0.2% | Sep 3, 2026 | MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allow... |
| CVE-2026-85434 | CRITICAL | 9.1 | 0.2% | Sep 3, 2026 | MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. A... |
| CVE-2026-85433 | CRITICAL | 9.8 | 0.3% | Sep 3, 2026 | MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to rec... |
| CVE-2026-85430 | CRITICAL | 9.1 | 1.0% | Sep 3, 2026 | MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams ... |
| CVE-2026-85428 | CRITICAL | 9.8 | 0.5% | Sep 3, 2026 | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that al... |
| CVE-2026-85426 | CRITICAL | 9.8 | 0.6% | Sep 3, 2026 | MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization.... |
| CVE-2026-85425 | CRITICAL | 9.8 | 1.0% | Sep 3, 2026 | MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes... |
| CVE-2026-85424 | CRITICAL | 9.8 | 0.5% | Sep 3, 2026 | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect wit... |
| CVE-2026-83711 | CRITICAL | 10 | 0.6% | Sep 3, 2026 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker... |
| CVE-2026-80098 | CRITICAL | 10 | 0.3% | Sep 3, 2026 | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges... |
| CVE-2026-70352 | CRITICAL | 10 | 0.6% | Sep 3, 2026 | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges ... |
| CVE-2026-65818 | CRITICAL | 9.9 | 0.3% | Sep 3, 2026 | Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-62916 | CRITICAL | 9.8 | 0.6% | Sep 3, 2026 | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevat... |
| CVE-2026-85224 | CRITICAL | 9.1 | 2.2% | Sep 3, 2026 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file... |
| CVE-2026-85223 | CRITICAL | 9.9 | 1.6% | Sep 3, 2026 | A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /... |
| CVE-2026-85222 | CRITICAL | 9.1 | — | Sep 3, 2026 | A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of... |
| CVE-2026-85061 | CRITICAL | 10 | 0.3% | Sep 3, 2026 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/do... |
| CVE-2026-85050 | CRITICAL | 9.6 | 0.3% | Sep 3, 2026 | Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute ... |
| CVE-2026-85047 | CRITICAL | 9.6 | 0.3% | Sep 3, 2026 | Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote at... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now