2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92729 | HIGH | 8.2 | 0.5% | Sep 16, 2026 | SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the H... |
| CVE-2026-86043 | HIGH | 7.5 | — | Sep 16, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWi... |
| CVE-2026-86003 | HIGH | 7.5 | 0.4% | Sep 16, 2026 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over... |
| CVE-2026-82399 | HIGH | 7.5 | 0.6% | Sep 16, 2026 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over... |
| CVE-2026-81876 | HIGH | 7.5 | — | Sep 16, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-81875 | HIGH | 7.5 | — | Sep 16, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-79298 | HIGH | 8.4 | 0.2% | Sep 16, 2026 | An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker... |
| CVE-2026-75516 | HIGH | 8.7 | 0.6% | Sep 16, 2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. ... |
| CVE-2026-63325 | HIGH | 7.8 | 0.2% | Sep 16, 2026 | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/r... |
| CVE-2026-63126 | HIGH | 7.5 | — | Sep 16, 2026 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire pro... |
| CVE-2026-46352 | HIGH | 7.5 | 0.5% | Sep 16, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. St... |
| CVE-2026-38999 | HIGH | 7.5 | 0.5% | Sep 16, 2026 | A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0... |
| CVE-2026-92719 | HIGH | 7.5 | 0.5% | Sep 16, 2026 | Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing at... |
| CVE-2026-92718 | HIGH | 7.3 | 0.1% | Sep 16, 2026 | Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content... |
| CVE-2026-92604 | HIGH | 8.1 | 0.5% | Sep 16, 2026 | Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows d... |
| CVE-2026-92406 | HIGH | 7.3 | — | Sep 16, 2026 | A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown f... |
| CVE-2026-85387 | HIGH | 7.1 | 0.2% | Sep 16, 2026 | Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the sta... |
| CVE-2026-47094 | HIGH | 8.8 | 0.5% | Sep 16, 2026 | SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to... |
| CVE-2026-92602 | HIGH | 7.1 | 0.4% | Sep 16, 2026 | TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigContro... |
| CVE-2026-92405 | HIGH | 7.3 | — | Sep 16, 2026 | A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element i... |
| CVE-2026-92401 | HIGH | 7.3 | — | Sep 16, 2026 | A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability aff... |
| CVE-2026-92399 | HIGH | 7.3 | — | Sep 16, 2026 | A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/uti... |
| CVE-2026-86359 | HIGH | 8.5 | — | Sep 16, 2026 | Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privile... |
| CVE-2026-86358 | HIGH | 8.8 | 0.3% | Sep 16, 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unau... |
| CVE-2026-85756 | HIGH | 7.5 | — | Sep 16, 2026 | SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now