2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51674 | CRITICAL | 9.8 | — | Aug 31, 2026 | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta... |
| CVE-2026-51672 | CRITICAL | 9.1 | — | Aug 31, 2026 | Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac... |
| CVE-2026-51670 | CRITICAL | 9.8 | — | Aug 31, 2026 | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta... |
| CVE-2026-51669 | CRITICAL | 9.1 | — | Aug 31, 2026 | Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacker... |
| CVE-2026-82695 | CRITICAL | 10 | — | Aug 31, 2026 | A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telne... |
| CVE-2026-82694 | CRITICAL | 10 | — | Aug 31, 2026 | A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the... |
| CVE-2026-82693 | CRITICAL | 10 | — | Aug 31, 2026 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the f... |
| CVE-2026-82692 | CRITICAL | 9.9 | — | Aug 31, 2026 | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-b... |
| CVE-2026-82691 | CRITICAL | 9.1 | 2.1% | Aug 31, 2026 | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue... |
| CVE-2026-82690 | CRITICAL | 9.1 | — | Aug 31, 2026 | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown funct... |
| CVE-2026-82689 | CRITICAL | 9.9 | — | Aug 31, 2026 | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown f... |
| CVE-2026-82688 | CRITICAL | 9.1 | 2.8% | Aug 31, 2026 | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts... |
| CVE-2026-49003 | CRITICAL | 9.6 | 0.8% | Aug 31, 2026 | Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring modu... |
| CVE-2026-82874 | CRITICAL | 9.9 | 0.3% | Aug 31, 2026 | ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organiza... |
| CVE-2026-82872 | CRITICAL | 9.1 | 0.3% | Aug 31, 2026 | ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace befor... |
| CVE-2026-82870 | CRITICAL | 9.6 | 0.2% | Aug 31, 2026 | ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any b... |
| CVE-2026-82860 | CRITICAL | 9.8 | 0.3% | Aug 31, 2026 | @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrat... |
| CVE-2026-82859 | CRITICAL | 9.8 | 0.3% | Aug 31, 2026 | hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role p... |
| CVE-2026-82858 | CRITICAL | 9.8 | 0.2% | Aug 31, 2026 | @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, a... |
| CVE-2026-82857 | CRITICAL | 9.8 | 0.3% | Aug 31, 2026 | hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that all... |
| CVE-2026-82856 | CRITICAL | 9.8 | 0.3% | Aug 31, 2026 | @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OID... |
| CVE-2026-82855 | CRITICAL | 9.8 | 0.3% | Aug 31, 2026 | @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-... |
| CVE-2026-82854 | CRITICAL | 9.8 | 1.1% | Aug 31, 2026 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an... |
| CVE-2026-19410 | CRITICAL | 9.4 | 0.2% | Aug 31, 2026 | An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on ... |
| CVE-2026-58574 | CRITICAL | 9.8 | 0.3% | Aug 31, 2026 | Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now