2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40141 | CRITICAL | 9.9 | 0.4% | Jul 6, 2026 | A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote ... |
| CVE-2026-40139 | CRITICAL | 9.8 | 0.7% | Jul 6, 2026 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp... |
| CVE-2026-5268 | CRITICAL | 9.1 | 0.4% | Jul 6, 2026 | An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products li... |
| CVE-2026-6900 | CRITICAL | 9.1 | — | Jul 6, 2026 | Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before... |
| CVE-2026-12686 | CRITICAL | 9.3 | — | Jul 6, 2026 | An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised acce... |
| CVE-2026-56140 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel ... |
| CVE-2026-53913 | CRITICAL | 9.8 | 0.6% | Jul 6, 2026 | Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerabili... |
| CVE-2026-48205 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dn... |
| CVE-2026-48204 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The... |
| CVE-2026-48203 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Valid... |
| CVE-2026-46456 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound m... |
| CVE-2026-46455 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper Ke... |
| CVE-2026-46454 | CRITICAL | 9.8 | 0.4% | Jul 6, 2026 | Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeu... |
| CVE-2026-43867 | CRITICAL | 9.8 | 0.2% | Jul 6, 2026 | Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-qu... |
| CVE-2026-40047 | CRITICAL | 9.1 | 1.3% | Jul 6, 2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling... |
| CVE-2026-24014 | CRITICAL | 9.8 | 0.4% | Jul 6, 2026 | Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to buil... |
| CVE-2026-24013 | CRITICAL | 9.1 | 0.4% | Jul 6, 2026 | Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validatio... |
| CVE-2026-6382 | CRITICAL | 9.1 | 0.5% | Jul 6, 2026 | The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pr... |
| CVE-2026-14808 | CRITICAL | 9.8 | 0.5% | Jul 6, 2026 | Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthe... |
| CVE-2026-14807 | CRITICAL | 9.8 | 0.5% | Jul 6, 2026 | ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attacke... |
| CVE-2026-59509 | CRITICAL | 9.2 | 0.3% | Jul 5, 2026 | An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote ... |
| CVE-2026-14535 | CRITICAL | 9.8 | 0.3% | Jul 4, 2026 | In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls A... |
| CVE-2026-58426 | CRITICAL | 9.6 | 0.2% | Jul 3, 2026 | Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state w... |
| CVE-2026-58422 | CRITICAL | 9.8 | 0.2% | Jul 3, 2026 | Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts |
| CVE-2026-57983 | CRITICAL | 10 | 0.5% | Jul 3, 2026 | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now