2026 CVE Vulnerabilities

50,987 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-42586HIGH7.1Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty...
CVE-2026-42585HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty inc...
CVE-2026-42583HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameD...
CVE-2026-42582HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks...
CVE-2026-42578HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's H...
CVE-2026-42577HIGH7.5Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll t...
CVE-2026-41132HIGH7.4CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-33583HIGH8.7Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via a...
CVE-2026-30906HIGH7.8Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user t...
CVE-2026-30905HIGH7.8External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11...
CVE-2026-0262HIGH7.5Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with...
CVE-2026-0261HIGH7.2Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator ...
CVE-2026-0259HIGH8.8An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables u...
CVE-2026-0251HIGH7.8Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to e...
CVE-2026-0250HIGH8.1A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle att...
CVE-2026-0247HIGH7.8Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attack...
CVE-2026-0246HIGH7.8A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally a...
CVE-2026-0244HIGH8.1An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (...
CVE-2026-0241HIGH7.2Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and per...
CVE-2026-0240HIGH8.7An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensi...
CVE-2026-0236HIGH7.8A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its A...
CVE-2026-45109HIGH7.5Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was ...
CVE-2026-44579HIGH7.5Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications ...
CVE-2026-44578HIGH8.6Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-h...
CVE-2026-44004HIGH7.5vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now