2026 CVE Vulnerabilities

52,054 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58162CRITICAL10The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue a...
CVE-2026-58161CRITICAL9.2Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affe...
CVE-2026-58160MEDIUM6.5Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0...
CVE-2026-58159HIGH8.2Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affect...
CVE-2026-58158HIGH8.2Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects A...
CVE-2026-58157HIGH8.7Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This i...
CVE-2026-50622HIGH8.8Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoi...
CVE-2026-23904HIGH7.3Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A re...
CVE-2026-18207MEDIUM6.5A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group m...
CVE-2026-18201MEDIUM5.5Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discov...
CVE-2026-9720MEDIUM4.3The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ...
CVE-2026-65325MEDIUM6.3Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the n...
CVE-2026-65324HIGH8.2Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client ...
CVE-2026-64557HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_...
CVE-2026-64556HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exe...
CVE-2026-58156MEDIUM6.3Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affe...
CVE-2026-58155CRITICAL9.3Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. ...
CVE-2026-58154CRITICAL9.2Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affe...
CVE-2026-58153HIGH8.3Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting H...
CVE-2026-58152MEDIUM6.9Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apa...
CVE-2026-58151HIGH8.7Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This ...
CVE-2026-13425HIGH7.2The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in al...
CVE-2026-11973MEDIUM4.9The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a...
CVE-2026-58150CRITICAL10Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This ...
CVE-2026-57834CRITICAL10Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Ser...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now