2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66761MEDIUM4.3SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s...
CVE-2026-66760MEDIUM6.4SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges...
CVE-2026-58248MEDIUM6.5SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci...
CVE-2026-58247MEDIUM5.3SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul...
CVE-2026-58245LOW3.8SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of th...
CVE-2026-58244MEDIUM4.3SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati...
CVE-2026-58243HIGH8.8SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attack...
CVE-2026-58241MEDIUM4.2SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privi...
CVE-2026-58239LOW3.7SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send ...
CVE-2026-58238MEDIUM5.9SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could...
CVE-2026-58237MEDIUM5.9WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l...
CVE-2026-58236MEDIUM5.5SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing securit...
CVE-2026-58235MEDIUM6.3SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer...
CVE-2026-58230HIGH7SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated att...
CVE-2026-44765HIGH7.3Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated...
CVE-2026-44764HIGH7.3Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated...
CVE-2026-44763HIGH7.6SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation...
CVE-2026-44762LOW3.7SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c...
CVE-2026-44758CRITICAL9.1SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted...
CVE-2026-40130MEDIUM5.3SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta...
CVE-2026-34265CRITICAL9.8SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol pars...
CVE-2026-8718HIGH8.4tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, T...
CVE-2026-48161CRITICAL9.3react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contain...
CVE-2026-11812LOW2.5The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single fi...
CVE-2026-11811LOW3.7The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now