2026 CVE Vulnerabilities

51,951 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14341MEDIUM4.9GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 1...
CVE-2026-13268HIGH7.8G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows ...
CVE-2026-13113MEDIUM5.3GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2...
CVE-2026-12436HIGH8.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 1...
CVE-2026-12357HIGH7.2Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability ...
CVE-2026-67429CRITICAL10Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fi...
CVE-2026-67428HIGH8.5Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi...
CVE-2026-67427HIGH8.6Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable ...
CVE-2026-67426CRITICAL9.3Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verifica...
CVE-2026-67425HIGH8.6Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys ...
CVE-2026-67424HIGH8.5Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, ht...
CVE-2026-67201HIGH8.6V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows...
CVE-2026-66737Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-62995LOW2.3joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-59898HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,...
CVE-2026-2482HIGH8.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which c...
CVE-2026-16328HIGH8.6In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing ...
CVE-2026-16326CRITICAL10In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may all...
CVE-2026-14529CRITICAL9.8IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 t...
CVE-2026-13346MEDIUM6.5pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo...
CVE-2026-12935HIGH8.7The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based b...
CVE-2026-10684LOW3In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredu...
CVE-2026-8497HIGH7.4Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0...
CVE-2026-59920MEDIUM6.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina...
CVE-2026-59919MEDIUM5.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now