2026 CVE Vulnerabilities
50,954 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45207 | HIGH | 7.8 | 0.2% | May 21, 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe... |
| CVE-2026-45206 | HIGH | 7.8 | 0.2% | May 21, 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe... |
| CVE-2026-34930 | HIGH | 7.8 | 0.2% | May 21, 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe... |
| CVE-2026-34929 | HIGH | 7.8 | 0.2% | May 21, 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe... |
| CVE-2026-34928 | HIGH | 7.8 | 0.2% | May 21, 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe... |
| CVE-2026-34927 | HIGH | 7.8 | 0.2% | May 21, 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe... |
| CVE-2026-2740 | HIGH | 8.4 | 1.7% | May 21, 2026 | Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus bef... |
| CVE-2026-45760 | HIGH | 8.1 | 0.3% | May 21, 2026 | (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vu... |
| CVE-2026-43502 | HIGH | 7.8 | 0.1% | May 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the me... |
| CVE-2026-43499 | HIGH | 7.8 | 0.8% | May 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in rem... |
| CVE-2026-43498 | HIGH | 7.8 | 0.1% | May 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Disallow re-exporting imported GEM obje... |
| CVE-2026-43497 | HIGH | 7.3 | 0.1% | May 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to preven... |
| CVE-2026-43495 | HIGH | 8.8 | 0.3% | May 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against messag... |
| CVE-2026-43494 | HIGH | 7.8 | 0.3% | May 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fail... |
| CVE-2026-45255 | HIGH | 7.5 | 0.3% | May 21, 2026 | When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and u... |
| CVE-2026-45253 | HIGH | 8.4 | 0.2% | May 21, 2026 | ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a... |
| CVE-2026-45251 | HIGH | 7.8 | 0.2% | May 21, 2026 | A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. B... |
| CVE-2026-42002 | HIGH | 7.5 | 0.3% | May 21, 2026 | Concurrency and locking defects in GSS-TSIG |
| CVE-2026-42001 | HIGH | 7.5 | 0.4% | May 21, 2026 | Insufficient Validation of Autoprimary SOA Queries |
| CVE-2026-42000 | HIGH | 8.6 | 0.2% | May 21, 2026 | Insufficient Validation of Names During AXFR |
| CVE-2026-39461 | HIGH | 8.8 | 0.2% | May 21, 2026 | libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for ... |
| CVE-2026-28764 | HIGH | 7.8 | 0.2% | May 21, 2026 | MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability |
| CVE-2026-9157 | HIGH | 8.6 | 0.1% | May 21, 2026 | Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remo... |
| CVE-2026-45250 | HIGH | 7.8 | 0.4% | May 21, 2026 | The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is ... |
| CVE-2026-44068 | HIGH | 7.6 | 0.3% | May 21, 2026 | Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now