2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80603 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by... |
| CVE-2026-80600 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after s... |
| CVE-2026-78032 | CRITICAL | 9.3 | 0.4% | Aug 28, 2026 | SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with... |
| CVE-2026-76581 | CRITICAL | 9.8 | 0.3% | Aug 28, 2026 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,... |
| CVE-2026-40541 | CRITICAL | 9 | 0.5% | Aug 28, 2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain ... |
| CVE-2026-82090 | CRITICAL | 9.2 | 0.3% | Aug 28, 2026 | Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alt... |
| CVE-2026-82082 | CRITICAL | 9.8 | 1.5% | Aug 28, 2026 | NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inje... |
| CVE-2026-78174 | CRITICAL | 9.3 | 0.3% | Aug 28, 2026 | WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-priv... |
| CVE-2026-61800 | CRITICAL | 9.1 | 0.6% | Aug 28, 2026 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I... |
| CVE-2026-19318 | CRITICAL | 9.3 | 0.5% | Aug 28, 2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated a... |
| CVE-2026-19315 | CRITICAL | 9.3 | 0.5% | Aug 28, 2026 | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to... |
| CVE-2026-19313 | CRITICAL | 9.3 | 0.5% | Aug 28, 2026 | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to ex... |
| CVE-2026-13086 | CRITICAL | 9.3 | 0.4% | Aug 28, 2026 | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security fe... |
| CVE-2026-78239 | CRITICAL | 9.8 | 0.6% | Aug 28, 2026 | Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote at... |
| CVE-2026-76943 | CRITICAL | 9.8 | 0.7% | Aug 28, 2026 | Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to byp... |
| CVE-2026-76179 | CRITICAL | 9.8 | 0.4% | Aug 28, 2026 | An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication ... |
| CVE-2026-75337 | CRITICAL | 9.8 | 0.4% | Aug 28, 2026 | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The us... |
| CVE-2026-73125 | CRITICAL | 9.8 | 0.5% | Aug 28, 2026 | Ebyte device web management interface does not consistently enforce authentication before granting access to administra... |
| CVE-2026-71187 | CRITICAL | 9.8 | 0.5% | Aug 28, 2026 | The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacke... |
| CVE-2026-69658 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level atta... |
| CVE-2026-68929 | CRITICAL | 9.3 | 0.3% | Aug 28, 2026 | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, th... |
| CVE-2026-50152 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2... |
| CVE-2026-74820 | CRITICAL | 10 | 0.2% | Aug 27, 2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulne... |
| CVE-2026-6876 | CRITICAL | 10 | 0.4% | Aug 27, 2026 | ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This securi... |
| CVE-2026-59313 | CRITICAL | 9.8 | 0.4% | Aug 27, 2026 | Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Ev... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now