2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77409 | HIGH | 8.2 | 0.5% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in conf... |
| CVE-2026-77407 | HIGH | 7 | 0.1% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as ... |
| CVE-2026-77406 | HIGH | 8.2 | 0.4% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount... |
| CVE-2026-77404 | HIGH | 8.7 | 0.1% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CAC... |
| CVE-2026-77403 | HIGH | 8.9 | 0.4% | Sep 16, 2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-ad... |
| CVE-2026-76825 | HIGH | 8.4 | — | Sep 16, 2026 | RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted en... |
| CVE-2026-76163 | HIGH | 7.5 | — | Sep 16, 2026 | If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of ... |
| CVE-2026-74909 | HIGH | 8.1 | — | Sep 16, 2026 | Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security p... |
| CVE-2026-63671 | HIGH | 8.1 | 0.5% | Sep 16, 2026 | MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nu... |
| CVE-2026-63128 | HIGH | 7.5 | — | Sep 16, 2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP s... |
| CVE-2026-63127 | HIGH | 8.2 | — | Sep 16, 2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in cr... |
| CVE-2026-19666 | HIGH | 7.5 | — | Sep 16, 2026 | On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a speci... |
| CVE-2026-18212 | HIGH | 7.5 | — | Sep 16, 2026 | A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management ... |
| CVE-2026-92469 | HIGH | 8.1 | 0.5% | Sep 16, 2026 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DE... |
| CVE-2026-92467 | HIGH | 8.3 | 0.4% | Sep 16, 2026 | zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/pass... |
| CVE-2026-92466 | HIGH | 8.8 | — | Sep 16, 2026 | zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.... |
| CVE-2026-92362 | HIGH | 7.3 | — | Sep 16, 2026 | A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-clie... |
| CVE-2026-92137 | HIGH | 8.8 | — | Sep 16, 2026 | Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framewor... |
| CVE-2026-92136 | HIGH | 8 | — | Sep 16, 2026 | Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the ... |
| CVE-2026-92135 | HIGH | 8 | — | Sep 16, 2026 | Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configurat... |
| CVE-2026-92134 | HIGH | 8 | — | Sep 16, 2026 | Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job confi... |
| CVE-2026-92129 | HIGH | 7.5 | 0.4% | Sep 16, 2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods ... |
| CVE-2026-92128 | HIGH | 7.5 | 0.2% | Sep 16, 2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming... |
| CVE-2026-92127 | HIGH | 8 | 0.5% | Sep 16, 2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item... |
| CVE-2026-92126 | HIGH | 8.5 | 0.5% | Sep 16, 2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now