2026 CVE Vulnerabilities
50,987 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42586 | HIGH | 7.1 | 0.2% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty... |
| CVE-2026-42585 | HIGH | 7.5 | 0.2% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty inc... |
| CVE-2026-42583 | HIGH | 7.5 | 0.4% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameD... |
| CVE-2026-42582 | HIGH | 7.5 | 0.4% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks... |
| CVE-2026-42578 | HIGH | 7.5 | 1.0% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's H... |
| CVE-2026-42577 | HIGH | 7.5 | 0.4% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll t... |
| CVE-2026-41132 | HIGH | 7.4 | 0.2% | May 13, 2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5... |
| CVE-2026-33583 | HIGH | 8.7 | 0.2% | May 13, 2026 | Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via a... |
| CVE-2026-30906 | HIGH | 7.8 | 0.1% | May 13, 2026 | Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user t... |
| CVE-2026-30905 | HIGH | 7.8 | 0.1% | May 13, 2026 | External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11... |
| CVE-2026-0262 | HIGH | 7.5 | 0.3% | May 13, 2026 | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with... |
| CVE-2026-0261 | HIGH | 7.2 | 1.3% | May 13, 2026 | Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator ... |
| CVE-2026-0259 | HIGH | 8.8 | 0.3% | May 13, 2026 | An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables u... |
| CVE-2026-0251 | HIGH | 7.8 | 0.2% | May 13, 2026 | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to e... |
| CVE-2026-0250 | HIGH | 8.1 | 0.2% | May 13, 2026 | A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle att... |
| CVE-2026-0247 | HIGH | 7.8 | 0.2% | May 13, 2026 | Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attack... |
| CVE-2026-0246 | HIGH | 7.8 | 0.1% | May 13, 2026 | A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally a... |
| CVE-2026-0244 | HIGH | 8.1 | 0.1% | May 13, 2026 | An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (... |
| CVE-2026-0241 | HIGH | 7.2 | 0.3% | May 13, 2026 | Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and per... |
| CVE-2026-0240 | HIGH | 8.7 | 0.2% | May 13, 2026 | An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensi... |
| CVE-2026-0236 | HIGH | 7.8 | 0.1% | May 13, 2026 | A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its A... |
| CVE-2026-45109 | HIGH | 7.5 | 0.6% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was ... |
| CVE-2026-44579 | HIGH | 7.5 | 0.7% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications ... |
| CVE-2026-44578 | HIGH | 8.6 | 38.9% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-h... |
| CVE-2026-44004 | HIGH | 7.5 | 0.4% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now