2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20342 | HIGH | 7.7 | — | Sep 16, 2026 | A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attack... |
| CVE-2026-20340 | HIGH | 8.8 | — | Sep 16, 2026 | A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands... |
| CVE-2026-20336 | HIGH | 8.8 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl... |
| CVE-2026-20335 | HIGH | 8.1 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl... |
| CVE-2026-20334 | HIGH | 8.4 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl... |
| CVE-2026-20333 | HIGH | 8.8 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl... |
| CVE-2026-20323 | HIGH | 8.3 | — | Sep 16, 2026 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD So... |
| CVE-2026-20300 | HIGH | 7.1 | — | Sep 16, 2026 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affect... |
| CVE-2026-20295 | HIGH | 8.6 | — | Sep 16, 2026 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD So... |
| CVE-2026-20250 | HIGH | 8.6 | — | Sep 16, 2026 | A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw... |
| CVE-2026-20249 | HIGH | 8.6 | — | Sep 16, 2026 | A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Se... |
| CVE-2026-20247 | HIGH | 7.5 | — | Sep 16, 2026 | A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affe... |
| CVE-2026-20222 | HIGH | 7.4 | — | Sep 16, 2026 | A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisc... |
| CVE-2026-20154 | HIGH | 8.6 | — | Sep 16, 2026 | A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security... |
| CVE-2026-20135 | HIGH | 8.6 | — | Sep 16, 2026 | A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unau... |
| CVE-2026-89084 | HIGH | 8.8 | — | Sep 16, 2026 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, ... |
| CVE-2026-87976 | HIGH | 8.1 | 0.4% | Sep 16, 2026 | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using g... |
| CVE-2026-87105 | HIGH | 8.8 | — | Sep 16, 2026 | Tanium addressed a SQL injection vulnerability in Threat Response. |
| CVE-2026-87024 | HIGH | 7.2 | — | Sep 16, 2026 | Tanium addressed a SQL injection vulnerability in Asset. |
| CVE-2026-86865 | HIGH | 7.2 | — | Sep 16, 2026 | Tanium addressed a SQL injection vulnerability in Asset. |
| CVE-2026-86831 | HIGH | 8.7 | — | Sep 16, 2026 | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v... |
| CVE-2026-86089 | HIGH | 7.1 | 0.3% | Sep 16, 2026 | Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API... |
| CVE-2026-76646 | HIGH | 7.5 | — | Sep 16, 2026 | A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentia... |
| CVE-2026-70469 | HIGH | 7.5 | 0.4% | Sep 16, 2026 | Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests th... |
| CVE-2026-20361 | HIGH | 8.8 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now