2026 CVE Vulnerabilities

51,080 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15977HIGH7.5SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf...
CVE-2026-15976CRITICAL9.8SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi...
CVE-2026-15974MEDIUM6.5SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitize...
CVE-2026-15971CRITICAL9.8SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when D...
CVE-2026-15969CRITICAL9.8SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl...
CVE-2026-14227MEDIUM6.9An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Sessi...
CVE-2026-13444HIGH8.1IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creatin...
CVE-2026-13435CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox impl...
CVE-2026-12943CRITICAL9.8IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power en...
CVE-2026-12942HIGH7.5IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c...
CVE-2026-12733HIGH7.5IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
CVE-2026-12118CRITICAL9.8IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary co...
CVE-2026-11904MEDIUM5.3IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident...
CVE-2026-10700MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API th...
CVE-2026-10695MEDIUM5.5IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated qu...
CVE-2026-10545HIGH7.5IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect ...
CVE-2026-10535HIGH7.8IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
CVE-2026-9322HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 a...
CVE-2026-66414MEDIUM6.1Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to ...
CVE-2026-62663HIGH7.5Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filt...
CVE-2026-54722HIGH8.7DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_...
CVE-2026-54522MEDIUM5.4MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::B...
CVE-2026-51295Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51294Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51293Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now