2026 CVE Vulnerabilities

53,576 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-55991MEDIUM5.9In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 asserti...
CVE-2026-55990MEDIUM5.9In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:'...
CVE-2026-55973HIGH7.5In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel...
CVE-2026-55717MEDIUM5.9In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: ...
CVE-2026-55708LOW3.1In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unboun...
CVE-2026-54478LOW3.7In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with ...
CVE-2026-53910LOW2.1diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in ...
CVE-2026-52863MEDIUM5.9In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together...
CVE-2026-50252CRITICAL9.3In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret...
CVE-2026-50251MEDIUM5.3In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value g...
CVE-2026-50248MEDIUM6.5In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that res...
CVE-2026-50243LOW3.7In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of ...
CVE-2026-50046MEDIUM5.9In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queri...
CVE-2026-50045MEDIUM5.3In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-s...
CVE-2026-46582LOW3.7In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be ...
CVE-2026-44690HIGH7.5In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with ...
CVE-2026-44687LOW3.7In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate l...
CVE-2026-44621MEDIUM5.9With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-...
CVE-2026-42955LOW3.7In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost do...
CVE-2026-41637LOW3.7In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted...
CVE-2026-40691HIGH7.5In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the r...
CVE-2026-32665HIGH7.5In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two b...
CVE-2026-16560MEDIUM5.3A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the s...
CVE-2026-16232CRITICAL9.8An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote at...
CVE-2026-14932MEDIUM6.5In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vuln...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now