2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-51674CRITICAL9.8Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta...
CVE-2026-51672CRITICAL9.1Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac...
CVE-2026-51670CRITICAL9.8Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta...
CVE-2026-51669CRITICAL9.1Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacker...
CVE-2026-82695CRITICAL10A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telne...
CVE-2026-82694CRITICAL10A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the...
CVE-2026-82693CRITICAL10A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the f...
CVE-2026-82692CRITICAL9.9A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-b...
CVE-2026-82691CRITICAL9.1A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue...
CVE-2026-82690CRITICAL9.1A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown funct...
CVE-2026-82689CRITICAL9.9A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown f...
CVE-2026-82688CRITICAL9.1A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts...
CVE-2026-49003CRITICAL9.6Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring modu...
CVE-2026-82874CRITICAL9.9ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organiza...
CVE-2026-82872CRITICAL9.1ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace befor...
CVE-2026-82870CRITICAL9.6ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any b...
CVE-2026-82860CRITICAL9.8@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrat...
CVE-2026-82859CRITICAL9.8hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role p...
CVE-2026-82858CRITICAL9.8@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, a...
CVE-2026-82857CRITICAL9.8hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that all...
CVE-2026-82856CRITICAL9.8@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OID...
CVE-2026-82855CRITICAL9.8@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-...
CVE-2026-82854CRITICAL9.8Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an...
CVE-2026-19410CRITICAL9.4An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on ...
CVE-2026-58574CRITICAL9.8Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now