2026 CVE Vulnerabilities

51,072 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58039LOW3.3A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wr...
CVE-2026-66720HIGH7.1The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy...
CVE-2026-66421CRITICAL9.3OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to ...
CVE-2026-66420HIGH8.8MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated...
CVE-2026-66369HIGH7.1The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-...
CVE-2026-66364HIGH7.1The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu...
CVE-2026-66360HIGH8.7The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A mis...
CVE-2026-66349MEDIUM6.9The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed ...
CVE-2026-65423HIGH8.8An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to t...
CVE-2026-65421HIGH7.1The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v...
CVE-2026-63550HIGH7.1The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess...
CVE-2026-63362HIGH8.2An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cau...
CVE-2026-63035HIGH8.1A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attack...
CVE-2026-63033MEDIUM6.9A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationO...
CVE-2026-61893MEDIUM6.9A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBu...
CVE-2026-56758MEDIUM6.9The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain...
CVE-2026-10031MEDIUM4.2SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-direc...
CVE-2026-68563MEDIUM5.5A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and th...
CVE-2026-68562MEDIUM6.2A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp ...
CVE-2026-64816HIGH7.1RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_proce...
CVE-2026-63559HIGH8.7An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to r...
CVE-2026-62845MEDIUM4.7Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv...
CVE-2026-62246HIGH8.5Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane dat...
CVE-2026-5846HIGH7.6The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 cert...
CVE-2026-38709CRITICAL9.8TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now