2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15747 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH... |
| CVE-2026-59891 | CRITICAL | 9.6 | 0.3% | Jul 14, 2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials... |
| CVE-2026-58644 | CRITICAL | 9.8 | 1.3% | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a ... |
| CVE-2026-56164 | CRITICAL | 9.8 | — | Jul 14, 2026 | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate p... |
| CVE-2026-55008 | CRITICAL | 9.6 | 0.9% | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows... |
| CVE-2026-54995 | CRITICAL | 9.8 | 0.6% | Jul 14, 2026 | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a ne... |
| CVE-2026-54433 | CRITICAL | 10 | 0.3% | Jul 14, 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai... |
| CVE-2026-54058 | CRITICAL | 9.1 | 0.4% | Jul 14, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename... |
| CVE-2026-50694 | CRITICAL | 9.8 | 0.6% | Jul 14, 2026 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a... |
| CVE-2026-50522 | CRITICAL | 9.8 | 21.0% | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a ... |
| CVE-2026-49798 | CRITICAL | 9.3 | 2.3% | Jul 14, 2026 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-49181 | CRITICAL | 9.8 | 0.8% | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over... |
| CVE-2026-49172 | CRITICAL | 9.8 | 0.7% | Jul 14, 2026 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. |
| CVE-2026-49164 | CRITICAL | 9.8 | 0.6% | Jul 14, 2026 | Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a ne... |
| CVE-2026-48561 | CRITICAL | 9.6 | 0.8% | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all... |
| CVE-2026-42990 | CRITICAL | 9.8 | 0.7% | Jul 14, 2026 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. |
| CVE-2026-15701 | CRITICAL | 9.8 | 0.8% | Jul 14, 2026 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Lo... |
| CVE-2026-62644 | CRITICAL | 9.8 | 0.2% | Jul 14, 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to u... |
| CVE-2026-62643 | CRITICAL | 10 | 0.2% | Jul 14, 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTM... |
| CVE-2026-60082 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle ... |
| CVE-2026-59836 | CRITICAL | 9.8 | 0.1% | Jul 14, 2026 | A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 thr... |
| CVE-2026-55954 | CRITICAL | 9.1 | 0.4% | Jul 14, 2026 | Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID ... |
| CVE-2026-58479 | CRITICAL | 9.8 | — | Jul 14, 2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional ... |
| CVE-2026-15265 | CRITICAL | 9.4 | 0.4% | Jul 14, 2026 | A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitr... |
| CVE-2026-10672 | CRITICAL | 9.1 | 0.4% | Jul 14, 2026 | subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now