2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-41106CRITICAL9.3Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege...
CVE-2026-26145CRITICAL9.8Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
CVE-2026-52830CRITICAL9.4fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t...
CVE-2026-38971CRITICAL9.1ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_contr...
CVE-2026-38968CRITICAL9.8ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session ide...
CVE-2026-59099CRITICAL9.3Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to...
CVE-2026-58466CRITICAL9.8AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers t...
CVE-2026-44935CRITICAL9.9Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.1...
CVE-2026-58455CRITICAL9.8Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to...
CVE-2026-56004CRITICAL10A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by ...
CVE-2026-55116CRITICAL9.8A malicious actor with access to the network and under certain network configurations could exploit an Improper Access C...
CVE-2026-55115CRITICAL9.9A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in Un...
CVE-2026-54408CRITICAL9.8A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote...
CVE-2026-54400CRITICAL9.1A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability ...
CVE-2026-50748CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-50747CRITICAL9.9A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu...
CVE-2026-50746CRITICAL10A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne...
CVE-2026-4767CRITICAL9.8Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abu...
CVE-2026-5524CRITICAL9.8The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in al...
CVE-2026-57683CRITICAL9.3Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
CVE-2026-57679CRITICAL9.3Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
CVE-2026-57677CRITICAL9.8Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
CVE-2026-57625CRITICAL9.6Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
CVE-2026-57624CRITICAL10Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
CVE-2026-57623CRITICAL9Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now