2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81096 | CRITICAL | 10 | 0.6% | Aug 27, 2026 | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authenticat... |
| CVE-2026-81094 | CRITICAL | 9.1 | 0.4% | Aug 27, 2026 | The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked... |
| CVE-2026-78251 | CRITICAL | 9.3 | 0.4% | Aug 27, 2026 | DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticate... |
| CVE-2026-75871 | CRITICAL | 9.6 | 0.2% | Aug 27, 2026 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 1... |
| CVE-2026-75357 | CRITICAL | 9.8 | 0.3% | Aug 27, 2026 | An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili... |
| CVE-2026-57499 | CRITICAL | 9.1 | 1.0% | Aug 27, 2026 | Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log... |
| CVE-2026-26897 | CRITICAL | 9.8 | 0.3% | Aug 27, 2026 | An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain ... |
| CVE-2026-16279 | CRITICAL | 9.3 | 0.3% | Aug 27, 2026 | An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Releas... |
| CVE-2026-81675 | CRITICAL | 9.3 | 0.3% | Aug 27, 2026 | The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter.... |
| CVE-2026-81674 | CRITICAL | 9.3 | 0.3% | Aug 27, 2026 | The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized in... |
| CVE-2026-81673 | CRITICAL | 9.3 | 0.4% | Aug 27, 2026 | The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. Th... |
| CVE-2026-81672 | CRITICAL | 9.3 | 0.3% | Aug 27, 2026 | SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video pa... |
| CVE-2026-74233 | CRITICAL | 9.8 | 3.4% | Aug 27, 2026 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE242... |
| CVE-2026-74232 | CRITICAL | 9.8 | 0.8% | Aug 27, 2026 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ... |
| CVE-2026-78292 | CRITICAL | 9.8 | 0.5% | Aug 27, 2026 | Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. |
| CVE-2026-78288 | CRITICAL | 9.3 | 0.4% | Aug 27, 2026 | Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. |
| CVE-2026-78286 | CRITICAL | 9.8 | 0.5% | Aug 27, 2026 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. |
| CVE-2026-78274 | CRITICAL | 9.1 | 0.5% | Aug 27, 2026 | Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. |
| CVE-2026-78260 | CRITICAL | 9.3 | 0.4% | Aug 27, 2026 | Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. |
| CVE-2026-32566 | CRITICAL | 9.8 | 0.4% | Aug 27, 2026 | Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. |
| CVE-2026-32479 | CRITICAL | 9.3 | 0.4% | Aug 27, 2026 | Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. |
| CVE-2026-77991 | CRITICAL | 9.4 | 0.4% | Aug 27, 2026 | Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The admin... |
| CVE-2026-77016 | CRITICAL | 9.6 | 0.2% | Aug 27, 2026 | The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate prof... |
| CVE-2026-59270 | CRITICAL | 9.1 | 0.3% | Aug 27, 2026 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative creden... |
| CVE-2026-47892 | CRITICAL | 9.8 | 0.4% | Aug 27, 2026 | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now