2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72536HIGH8.6A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mani...
CVE-2026-72535HIGH8.6A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint...
CVE-2026-72534HIGH8.8A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s...
CVE-2026-72533HIGH8.8An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas...
CVE-2026-50237HIGH7.4A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace t...
CVE-2026-50236HIGH7.4An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are...
CVE-2026-13739HIGH8.8A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability relate...
CVE-2026-13738CRITICAL9.2CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft...
CVE-2026-13737CRITICAL9.2CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg...
CVE-2026-58231CRITICAL10SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially craf...
CVE-2026-73162MEDIUM5.3Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /acco...
CVE-2026-33922MEDIUM6.8A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to in...
CVE-2026-33921MEDIUM5.2The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver ...
CVE-2026-73161MEDIUM5.1Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feat...
CVE-2026-73160HIGH8.7Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoi...
CVE-2026-73159MEDIUM5.1Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's ...
CVE-2026-73158MEDIUM5.1Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont...
CVE-2026-73157LOW2.3Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface usi...
CVE-2026-72694HIGH7.1A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low...
CVE-2026-72693HIGH7.8`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged ...
CVE-2026-71218MEDIUM5.3A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function,...
CVE-2026-71217HIGH7.5A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON wit...
CVE-2026-15567HIGH7.5A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token dec...
CVE-2026-15565HIGH7.5A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on...
CVE-2026-15563HIGH7.4A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now