2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20286 | MEDIUM | 4.3 | — | Sep 16, 2026 | A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticat... |
| CVE-2026-20285 | MEDIUM | 4.3 | — | Sep 16, 2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Iden... |
| CVE-2026-20283 | MEDIUM | 6.5 | — | Sep 16, 2026 | A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbi... |
| CVE-2026-20282 | MEDIUM | 4.9 | 0.6% | Sep 16, 2026 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying oper... |
| CVE-2026-20248 | MEDIUM | 6.8 | — | Sep 16, 2026 | A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software a... |
| CVE-2026-20235 | MEDIUM | 4.9 | 0.3% | Sep 16, 2026 | A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view... |
| CVE-2026-20121 | MEDIUM | 5.3 | — | Sep 16, 2026 | A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adapt... |
| CVE-2026-20120 | MEDIUM | 5.8 | — | Sep 16, 2026 | A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adapt... |
| CVE-2026-20072 | MEDIUM | 4.9 | 0.4% | Sep 16, 2026 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obta... |
| CVE-2026-92526 | MEDIUM | 6.3 | 0.2% | Sep 16, 2026 | A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/... |
| CVE-2026-92475 | MEDIUM | 5.3 | 0.1% | Sep 16, 2026 | A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/ut... |
| CVE-2026-87116 | MEDIUM | 6.5 | — | Sep 16, 2026 | Tanium addressed a server-side request forgery vulnerability in Threat Response. |
| CVE-2026-87113 | MEDIUM | 6.3 | — | Sep 16, 2026 | Tanium addressed an improper access controls vulnerability in Threat Response. |
| CVE-2026-87076 | MEDIUM | 6.5 | — | Sep 16, 2026 | Tanium addressed an information disclosure vulnerability in Discover. |
| CVE-2026-82561 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a cl... |
| CVE-2026-81866 | MEDIUM | 4.3 | 0.4% | Sep 16, 2026 | Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not en... |
| CVE-2026-62949 | MEDIUM | 6.5 | — | Sep 16, 2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to... |
| CVE-2026-92417 | MEDIUM | 6.5 | 0.6% | Sep 16, 2026 | A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the lib... |
| CVE-2026-81176 | MEDIUM | 5.3 | — | Sep 16, 2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ... |
| CVE-2026-77360 | MEDIUM | 6.3 | — | Sep 16, 2026 | oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, th... |
| CVE-2026-75025 | MEDIUM | 4.7 | — | Sep 16, 2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict serv... |
| CVE-2026-73462 | MEDIUM | 6.5 | — | Sep 16, 2026 | On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by ... |
| CVE-2026-73457 | MEDIUM | 5.3 | — | Sep 16, 2026 | Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI)... |
| CVE-2026-73443 | MEDIUM | 4.7 | — | Sep 16, 2026 | On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within... |
| CVE-2026-63225 | MEDIUM | 4.4 | — | Sep 16, 2026 | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the spl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now