2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-96416 | MEDIUM | 5.5 | — | Sep 29, 2026 | IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96415 | MEDIUM | 5.5 | — | Sep 29, 2026 | Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95395 | MEDIUM | 5.5 | — | Sep 29, 2026 | IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95394 | MEDIUM | 4.7 | — | Sep 29, 2026 | Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95393 | MEDIUM | 4.7 | — | Sep 29, 2026 | CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95392 | MEDIUM | 5.5 | — | Sep 29, 2026 | MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95391 | MEDIUM | 5.5 | — | Sep 29, 2026 | ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service |
| CVE-2026-95390 | MEDIUM | 5.5 | — | Sep 29, 2026 | PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service |
| CVE-2026-95389 | HIGH | 8.1 | — | Sep 29, 2026 | SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95388 | MEDIUM | 5.5 | — | Sep 29, 2026 | Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95387 | HIGH | 8.1 | — | Sep 29, 2026 | SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95386 | MEDIUM | 5.5 | — | Sep 29, 2026 | TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service |
| CVE-2026-8937 | MEDIUM | 4.3 | — | Sep 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 1... |
| CVE-2026-8067 | MEDIUM | 6.5 | — | Sep 29, 2026 | An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated ... |
| CVE-2026-8066 | CRITICAL | 9.1 | — | Sep 29, 2026 | A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allow... |
| CVE-2026-8065 | CRITICAL | 9.1 | — | Sep 29, 2026 | An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions all... |
| CVE-2026-86843 | — | — | — | Sep 29, 2026 | The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained... |
| CVE-2026-84739 | HIGH | 8.7 | — | Sep 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and ... |
| CVE-2026-81930 | — | — | — | Sep 29, 2026 | Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating... |
| CVE-2026-81914 | — | — | — | Sep 29, 2026 | Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly i... |
| CVE-2026-81862 | — | — | — | Sep 29, 2026 | Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperato... |
| CVE-2026-7395 | HIGH | 8.5 | — | Sep 29, 2026 | Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file... |
| CVE-2026-76720 | MEDIUM | 4.3 | — | Sep 29, 2026 | A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect. |
| CVE-2026-76719 | HIGH | 8.2 | — | Sep 29, 2026 | A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unau... |
| CVE-2026-76718 | HIGH | 8.2 | — | Sep 29, 2026 | A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthoriz... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now