2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85731 | HIGH | 8.8 | — | Sep 16, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked w... |
| CVE-2026-71180 | HIGH | 7.8 | 0.1% | Sep 16, 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privi... |
| CVE-2026-71179 | HIGH | 7.8 | 0.5% | Sep 16, 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used ... |
| CVE-2026-68904 | HIGH | 7 | — | Sep 16, 2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using th... |
| CVE-2026-59974 | HIGH | 7.8 | — | Sep 16, 2026 | Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human language... |
| CVE-2026-42784 | HIGH | 7.4 | 0.2% | Sep 16, 2026 | A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags su... |
| CVE-2026-92626 | HIGH | 7.5 | — | Sep 16, 2026 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardint... |
| CVE-2026-92625 | HIGH | 7.5 | — | Sep 16, 2026 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/r... |
| CVE-2026-61595 | HIGH | 7.7 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-61593 | HIGH | 8.1 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-17526 | HIGH | 7.2 | — | Sep 16, 2026 | Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the... |
| CVE-2026-92566 | HIGH | 8.2 | 0.5% | Sep 16, 2026 | DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that a... |
| CVE-2026-92380 | HIGH | 7.3 | — | Sep 16, 2026 | A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file core... |
| CVE-2026-92366 | HIGH | 7.3 | — | Sep 16, 2026 | A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search... |
| CVE-2026-92087 | HIGH | 8.1 | — | Sep 16, 2026 | @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route... |
| CVE-2026-88064 | HIGH | 8.8 | — | Sep 16, 2026 | Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backst... |
| CVE-2026-84997 | HIGH | 7.5 | — | Sep 16, 2026 | react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, Re... |
| CVE-2026-84860 | HIGH | 8.8 | — | Sep 16, 2026 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints b... |
| CVE-2026-84858 | HIGH | 8.8 | — | Sep 16, 2026 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Byp... |
| CVE-2026-82964 | HIGH | 8.8 | — | Sep 16, 2026 | Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-... |
| CVE-2026-82410 | HIGH | 8.7 | — | Sep 16, 2026 | Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middlew... |
| CVE-2026-80274 | HIGH | 7.5 | — | Sep 16, 2026 | If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a val... |
| CVE-2026-79651 | HIGH | 7.5 | — | Sep 16, 2026 | A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service respo... |
| CVE-2026-77412 | HIGH | 8.9 | 0.4% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-ar... |
| CVE-2026-77410 | HIGH | 8.9 | 0.4% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the messa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now