2026 CVE Vulnerabilities

51,951 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-59901HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-59900MEDIUM5.3Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-59899HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-54705MEDIUM6.3MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode conten...
CVE-2026-41939CRITICAL9.8Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final manag...
CVE-2026-40272HIGH7Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted k...
CVE-2026-18236CRITICAL9.3A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker wh...
CVE-2026-14266HIGH7.87-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote ...
CVE-2026-13723MEDIUM6.5A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrar...
CVE-2026-8339HIGH8.7A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclus...
CVE-2026-8338CRITICAL9.2A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026....
CVE-2026-67194HIGH7.1Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process...
CVE-2026-64560HIGH7.8In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader ...
CVE-2026-64559HIGH7.8In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl ...
CVE-2026-64558HIGH7.8In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler imple...
CVE-2026-54727HIGH8.2proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink ...
CVE-2026-54693HIGH8.2ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4...
CVE-2026-54680CRITICAL9.9Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd...
CVE-2026-54574HIGH8.2proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain ta...
CVE-2026-52791LOW2fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branc...
CVE-2026-51992Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL inte...
CVE-2026-20316MEDIUM5.3A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti...
CVE-2026-18257MEDIUM5.6Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a cert...
CVE-2026-18255HIGH7.2A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repo...
CVE-2026-16729MEDIUM6.5undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now