2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86443 | MEDIUM | 6.9 | 0.1% | Sep 16, 2026 | Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an ... |
| CVE-2026-84501 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a cra... |
| CVE-2026-84439 | MEDIUM | 5.3 | 0.3% | Sep 16, 2026 | When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields int... |
| CVE-2026-77190 | MEDIUM | 6.5 | — | Sep 16, 2026 | On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to ... |
| CVE-2026-76151 | MEDIUM | 4.6 | — | Sep 16, 2026 | Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Gr... |
| CVE-2026-73469 | MEDIUM | 5.8 | 0.3% | Sep 16, 2026 | When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain ... |
| CVE-2026-73468 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentia... |
| CVE-2026-73440 | MEDIUM | 4.2 | 0.3% | Sep 16, 2026 | On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remo... |
| CVE-2026-73438 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated... |
| CVE-2026-73436 | MEDIUM | 6.5 | 0.2% | Sep 16, 2026 | On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 p... |
| CVE-2026-19640 | MEDIUM | 4.2 | 0.2% | Sep 16, 2026 | On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interfa... |
| CVE-2026-92081 | MEDIUM | 5.9 | 0.4% | Sep 16, 2026 | fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a respon... |
| CVE-2026-89186 | MEDIUM | 6.3 | 0.4% | Sep 16, 2026 | Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and ser... |
| CVE-2026-88255 | MEDIUM | 6.3 | 0.4% | Sep 16, 2026 | Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Te... |
| CVE-2026-86465 | MEDIUM | 6.5 | 0.2% | Sep 16, 2026 | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled... |
| CVE-2026-86338 | MEDIUM | 6 | 0.3% | Sep 16, 2026 | Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not... |
| CVE-2026-82720 | MEDIUM | 5.9 | 0.3% | Sep 16, 2026 | NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs... |
| CVE-2026-78227 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC... |
| CVE-2026-77955 | MEDIUM | 4.4 | 0.1% | Sep 16, 2026 | In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) ... |
| CVE-2026-73463 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured... |
| CVE-2026-73445 | MEDIUM | 4.9 | 0.3% | Sep 16, 2026 | On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may ... |
| CVE-2026-92091 | MEDIUM | 5.9 | 0.5% | Sep 16, 2026 | A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using ... |
| CVE-2026-89207 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (... |
| CVE-2026-86341 | MEDIUM | 4.4 | 0.3% | Sep 16, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3... |
| CVE-2026-81326 | MEDIUM | 6.8 | 0.1% | Sep 16, 2026 | QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the aff... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now