2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82277 | CRITICAL | 9.8 | 0.8% | Aug 28, 2026 | Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentic... |
| CVE-2026-82266 | CRITICAL | 9.8 | 0.6% | Aug 28, 2026 | Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating un... |
| CVE-2026-55634 | CRITICAL | 9.9 | 0.4% | Aug 28, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-defi... |
| CVE-2026-55565 | CRITICAL | 9.9 | 0.5% | Aug 28, 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-... |
| CVE-2026-55559 | CRITICAL | 9.8 | 0.6% | Aug 28, 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances an... |
| CVE-2026-55511 | CRITICAL | 9.1 | 0.7% | Aug 28, 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiv... |
| CVE-2026-55378 | CRITICAL | 9.3 | 0.6% | Aug 28, 2026 | JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 until 1.3.1-beta.2, the PR Branch Checker workflow... |
| CVE-2026-55248 | CRITICAL | 9.1 | 0.3% | Aug 28, 2026 | plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and ... |
| CVE-2026-55247 | CRITICAL | 9.1 | 0.3% | Aug 28, 2026 | plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in sr... |
| CVE-2026-55220 | CRITICAL | 9.3 | 0.5% | Aug 28, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\... |
| CVE-2026-55068 | CRITICAL | 9.3 | 0.4% | Aug 28, 2026 | free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handle... |
| CVE-2026-54755 | CRITICAL | 9.6 | 0.4% | Aug 28, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in c... |
| CVE-2026-54754 | CRITICAL | 9.6 | 0.3% | Aug 28, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/ka... |
| CVE-2026-54745 | CRITICAL | 10 | 0.4% | Aug 28, 2026 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the... |
| CVE-2026-51660 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate... |
| CVE-2026-51657 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack... |
| CVE-2026-51649 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att... |
| CVE-2026-51646 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at... |
| CVE-2026-51645 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta... |
| CVE-2026-51643 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers... |
| CVE-2026-51636 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att... |
| CVE-2026-51628 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat... |
| CVE-2026-51626 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac... |
| CVE-2026-51622 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers... |
| CVE-2026-51611 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now