2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84465 | HIGH | 7.1 | 0.1% | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signa... |
| CVE-2026-84464 | HIGH | 7.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source featur... |
| CVE-2026-84463 | MEDIUM | 6.3 | 0.1% | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing r... |
| CVE-2026-84461 | MEDIUM | 6.9 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an att... |
| CVE-2026-84460 | MEDIUM | 5.3 | 0.3% | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the ... |
| CVE-2026-84458 | CRITICAL | 9.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on ... |
| CVE-2026-63216 | MEDIUM | 5.3 | 0.2% | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are render... |
| CVE-2026-63208 | MEDIUM | 5.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails... |
| CVE-2026-63207 | MEDIUM | 6.9 | 0.2% | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator c... |
| CVE-2026-63206 | MEDIUM | 5.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which block... |
| CVE-2026-63205 | MEDIUM | 5.1 | 0.3% | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email s... |
| CVE-2026-63204 | LOW | 2.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent per... |
| CVE-2026-63006 | MEDIUM | 5.3 | 0.5% | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound ... |
| CVE-2026-61855 | MEDIUM | 5.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad... |
| CVE-2026-55217 | MEDIUM | 5.3 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authentica... |
| CVE-2026-55214 | HIGH | 8.5 | 0.3% | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store... |
| CVE-2026-53629 | HIGH | 7.1 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ ... |
| CVE-2026-53628 | MEDIUM | 5.9 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding th... |
| CVE-2026-53627 | MEDIUM | 6 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user c... |
| CVE-2026-53626 | HIGH | 7.1 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission ... |
| CVE-2026-53625 | HIGH | 7.5 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate... |
| CVE-2026-53610 | HIGH | 7.5 | 0.4% | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a das... |
| CVE-2026-49470 | HIGH | 7.7 | 0.4% | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password veri... |
| CVE-2026-49469 | MEDIUM | 4.6 | 0.4% | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner o... |
| CVE-2026-48482 | CRITICAL | 9.4 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form imp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now