2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93435 | HIGH | 7.5 | 0.4% | Sep 17, 2026 | redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious ... |
| CVE-2026-87886 | HIGH | 7.8 | — | Sep 17, 2026 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin ... |
| CVE-2026-85917 | HIGH | 7.5 | 1.0% | Sep 17, 2026 | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a netw... |
| CVE-2026-85885 | HIGH | 8.8 | 1.0% | Sep 17, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized... |
| CVE-2026-78501 | HIGH | 7.4 | — | Sep 17, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business ... |
| CVE-2026-77903 | HIGH | 8.1 | 0.7% | Sep 17, 2026 | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a ne... |
| CVE-2026-68791 | HIGH | 7.5 | 1.0% | Sep 17, 2026 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network... |
| CVE-2026-93426 | HIGH | 8.5 | 0.4% | Sep 17, 2026 | SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, ... |
| CVE-2026-86688 | HIGH | 7.4 | — | Sep 17, 2026 | Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier ... |
| CVE-2026-54671 | HIGH | 8.8 | — | Sep 17, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource arra... |
| CVE-2026-54647 | HIGH | 7.2 | 1.9% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates t... |
| CVE-2026-54646 | HIGH | 7.2 | 1.4% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator... |
| CVE-2026-54634 | HIGH | 7.3 | 0.4% | Sep 17, 2026 | Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld ... |
| CVE-2026-54612 | HIGH | 8.8 | — | Sep 17, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until... |
| CVE-2026-54608 | HIGH | 7.1 | 0.1% | Sep 17, 2026 | MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/Syste... |
| CVE-2026-54520 | HIGH | 8.1 | 0.5% | Sep 17, 2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ... |
| CVE-2026-54519 | HIGH | 8.8 | 0.5% | Sep 17, 2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ... |
| CVE-2026-54507 | HIGH | 8.4 | — | Sep 17, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5... |
| CVE-2026-54506 | HIGH | 7.6 | 0.3% | Sep 17, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5... |
| CVE-2026-54343 | HIGH | 8.7 | 0.5% | Sep 17, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ... |
| CVE-2026-53557 | HIGH | 7.7 | 0.3% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated use... |
| CVE-2026-53554 | HIGH | 7.3 | 0.4% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat... |
| CVE-2026-53534 | HIGH | 7.5 | 0.4% | Sep 17, 2026 | JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef'... |
| CVE-2026-50158 | HIGH | 7.7 | 0.2% | Sep 17, 2026 | yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool ... |
| CVE-2026-93393 | HIGH | 8.1 | — | Sep 17, 2026 | A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platf... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now