2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76197 | CRITICAL | 10 | 1.6% | Aug 25, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co... |
| CVE-2026-76195 | CRITICAL | 10 | 1.6% | Aug 25, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co... |
| CVE-2026-76193 | CRITICAL | 10 | 0.7% | Aug 25, 2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbi... |
| CVE-2026-19912 | CRITICAL | 9.8 | 0.6% | Aug 25, 2026 | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by ... |
| CVE-2026-79675 | CRITICAL | 9.8 | 0.4% | Aug 25, 2026 | NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, a... |
| CVE-2026-55640 | CRITICAL | 9.1 | 0.5% | Aug 25, 2026 | Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.11... |
| CVE-2026-55546 | CRITICAL | 9.8 | 0.4% | Aug 25, 2026 | QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engin... |
| CVE-2026-55536 | CRITICAL | 9.1 | 0.3% | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome ex... |
| CVE-2026-16286 | CRITICAL | 9.8 | 0.3% | Aug 25, 2026 | Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware... |
| CVE-2026-77998 | CRITICAL | 10 | 0.3% | Aug 25, 2026 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML ... |
| CVE-2026-75803 | CRITICAL | 9.1 | 0.2% | Aug 25, 2026 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying th... |
| CVE-2026-63073 | CRITICAL | 9.8 | 0.9% | Aug 25, 2026 | Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the f... |
| CVE-2026-79657 | CRITICAL | 9.8 | 1.2% | Aug 25, 2026 | NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entir... |
| CVE-2026-57910 | CRITICAL | 9.3 | 0.2% | Aug 25, 2026 | Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agen... |
| CVE-2026-57909 | CRITICAL | 9.4 | 0.3% | Aug 25, 2026 | A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to e... |
| CVE-2026-55976 | CRITICAL | 9.1 | 0.4% | Aug 25, 2026 | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated r... |
| CVE-2026-49845 | CRITICAL | 9.8 | 0.3% | Aug 25, 2026 | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows... |
| CVE-2026-77138 | CRITICAL | 9.3 | 0.4% | Aug 25, 2026 | The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserial... |
| CVE-2026-77136 | CRITICAL | 9.5 | 0.6% | Aug 25, 2026 | The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly i... |
| CVE-2026-63586 | CRITICAL | 9.8 | 0.5% | Aug 25, 2026 | The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication u... |
| CVE-2026-59769 | CRITICAL | 9.1 | 0.3% | Aug 25, 2026 | FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel'... |
| CVE-2026-13214 | CRITICAL | 9.8 | 0.5% | Aug 25, 2026 | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When hand... |
| CVE-2026-78683 | CRITICAL | 9.6 | 0.3% | Aug 25, 2026 | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the Transition... |
| CVE-2026-78676 | CRITICAL | 9.8 | 0.4% | Aug 25, 2026 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting do... |
| CVE-2026-56710 | CRITICAL | 9.8 | 0.3% | Aug 25, 2026 | Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now