2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47116 | CRITICAL | 9.8 | 0.5% | Sep 22, 2026 | LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stor... |
| CVE-2026-28324 | CRITICAL | 9.8 | 0.7% | Sep 22, 2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability ... |
| CVE-2026-91130 | CRITICAL | 9.3 | 0.5% | Sep 22, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Stat... |
| CVE-2026-88414 | CRITICAL | 9.8 | 0.2% | Sep 22, 2026 | MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/ver... |
| CVE-2026-82000 | CRITICAL | 9.6 | — | Sep 22, 2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i... |
| CVE-2026-81995 | CRITICAL | 9.1 | — | Sep 22, 2026 | Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitr... |
| CVE-2026-77254 | CRITICAL | 9.1 | 0.6% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, re... |
| CVE-2026-75745 | CRITICAL | 10 | 1.2% | Sep 22, 2026 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrar... |
| CVE-2026-75698 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulner... |
| CVE-2026-75697 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to in... |
| CVE-2026-75689 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to in... |
| CVE-2026-75686 | CRITICAL | 9.3 | 1.1% | Sep 22, 2026 | Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in... |
| CVE-2026-75684 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to in... |
| CVE-2026-75682 | CRITICAL | 9.9 | 0.5% | Sep 22, 2026 | Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vul... |
| CVE-2026-57149 | CRITICAL | 9.9 | 0.6% | Sep 22, 2026 | plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of po... |
| CVE-2026-37604 | CRITICAL | 9.8 | 0.3% | Sep 22, 2026 | pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/... |
| CVE-2026-89276 | CRITICAL | 9.9 | 0.5% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t... |
| CVE-2026-89275 | CRITICAL | 10 | 1.2% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t... |
| CVE-2026-84412 | CRITICAL | 10 | 1.2% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t... |
| CVE-2026-83660 | CRITICAL | 10 | 0.3% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv... |
| CVE-2026-82443 | CRITICAL | 9.9 | 0.7% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv... |
| CVE-2026-82013 | CRITICAL | 9.9 | 0.8% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv... |
| CVE-2026-82011 | CRITICAL | 9.1 | 0.6% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-82010 | CRITICAL | 9.9 | 1.0% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-82009 | CRITICAL | 9.1 | 1.0% | Sep 22, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now