2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41106 | CRITICAL | 9.3 | 0.5% | Jul 2, 2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege... |
| CVE-2026-26145 | CRITICAL | 9.8 | 0.3% | Jul 2, 2026 | Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-52830 | CRITICAL | 9.4 | 0.4% | Jul 2, 2026 | fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t... |
| CVE-2026-38971 | CRITICAL | 9.1 | 0.5% | Jul 2, 2026 | ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_contr... |
| CVE-2026-38968 | CRITICAL | 9.8 | 0.4% | Jul 2, 2026 | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session ide... |
| CVE-2026-59099 | CRITICAL | 9.3 | 0.4% | Jul 2, 2026 | Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to... |
| CVE-2026-58466 | CRITICAL | 9.8 | 0.5% | Jul 2, 2026 | AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers t... |
| CVE-2026-44935 | CRITICAL | 9.9 | 0.6% | Jul 2, 2026 | Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.1... |
| CVE-2026-58455 | CRITICAL | 9.8 | 1.2% | Jul 2, 2026 | Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to... |
| CVE-2026-56004 | CRITICAL | 10 | — | Jul 2, 2026 | A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by ... |
| CVE-2026-55116 | CRITICAL | 9.8 | 0.2% | Jul 2, 2026 | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access C... |
| CVE-2026-55115 | CRITICAL | 9.9 | 0.2% | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in Un... |
| CVE-2026-54408 | CRITICAL | 9.8 | 0.3% | Jul 2, 2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote... |
| CVE-2026-54400 | CRITICAL | 9.1 | 0.3% | Jul 2, 2026 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability ... |
| CVE-2026-50748 | CRITICAL | 9.9 | 0.8% | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-50747 | CRITICAL | 9.9 | 0.2% | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu... |
| CVE-2026-50746 | CRITICAL | 10 | 2.5% | Jul 2, 2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne... |
| CVE-2026-4767 | CRITICAL | 9.8 | — | Jul 2, 2026 | Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abu... |
| CVE-2026-5524 | CRITICAL | 9.8 | — | Jul 2, 2026 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in al... |
| CVE-2026-57683 | CRITICAL | 9.3 | — | Jul 2, 2026 | Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. |
| CVE-2026-57679 | CRITICAL | 9.3 | — | Jul 2, 2026 | Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions. |
| CVE-2026-57677 | CRITICAL | 9.8 | — | Jul 2, 2026 | Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. |
| CVE-2026-57625 | CRITICAL | 9.6 | — | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions. |
| CVE-2026-57624 | CRITICAL | 10 | — | Jul 2, 2026 | Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. |
| CVE-2026-57623 | CRITICAL | 9 | — | Jul 2, 2026 | Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now