2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-40141CRITICAL9.9A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote ...
CVE-2026-40139CRITICAL9.8A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp...
CVE-2026-5268CRITICAL9.1An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products li...
CVE-2026-6900CRITICAL9.1Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before...
CVE-2026-12686CRITICAL9.3An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised acce...
CVE-2026-56140CRITICAL9.8Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel ...
CVE-2026-53913CRITICAL9.8Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerabili...
CVE-2026-48205CRITICAL9.1Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dn...
CVE-2026-48204CRITICAL9.8Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The...
CVE-2026-48203CRITICAL9.1Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Valid...
CVE-2026-46456CRITICAL9.8Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound m...
CVE-2026-46455CRITICAL9.8Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper Ke...
CVE-2026-46454CRITICAL9.8Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeu...
CVE-2026-43867CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-qu...
CVE-2026-40047CRITICAL9.1Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling...
CVE-2026-24014CRITICAL9.8Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to buil...
CVE-2026-24013CRITICAL9.1Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validatio...
CVE-2026-6382CRITICAL9.1The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pr...
CVE-2026-14808CRITICAL9.8Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthe...
CVE-2026-14807CRITICAL9.8ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attacke...
CVE-2026-59509CRITICAL9.2An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote ...
CVE-2026-14535CRITICAL9.8In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls A...
CVE-2026-58426CRITICAL9.6Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state w...
CVE-2026-58422CRITICAL9.8Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-57983CRITICAL10Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now