2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-96416MEDIUM5.5IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96415MEDIUM5.5Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95395MEDIUM5.5IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95394MEDIUM4.7Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95393MEDIUM4.7CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95392MEDIUM5.5MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95391MEDIUM5.5ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service
CVE-2026-95390MEDIUM5.5PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service
CVE-2026-95389HIGH8.1SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95388MEDIUM5.5Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95387HIGH8.1SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95386MEDIUM5.5TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service
CVE-2026-8937MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 1...
CVE-2026-8067MEDIUM6.5An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated ...
CVE-2026-8066CRITICAL9.1A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allow...
CVE-2026-8065CRITICAL9.1An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions all...
CVE-2026-86843——The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained...
CVE-2026-84739HIGH8.7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and ...
CVE-2026-81930——Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating...
CVE-2026-81914——Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly i...
CVE-2026-81862——Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperato...
CVE-2026-7395HIGH8.5Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file...
CVE-2026-76720MEDIUM4.3A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.
CVE-2026-76719HIGH8.2A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unau...
CVE-2026-76718HIGH8.2A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthoriz...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now