2026 CVE Vulnerabilities

53,206 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-23457HIGH8.6In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32...
CVE-2026-23456HIGH8.2In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decod...
CVE-2026-23454HIGH7In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_c...
CVE-2026-23453HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: Fix memory leak in XDP_DROP ...
CVE-2026-23451HIGH7.5In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_he...
CVE-2026-23449HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: Fix double-free in teql_master_xmi...
CVE-2026-23448HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes b...
CVE-2026-23447HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes b...
CVE-2026-23432HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mshv: Fix use-after-free in mshv_map_user_memory er...
CVE-2026-23428HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of share_conf in compound...
CVE-2026-23427HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in durable v2 replay of a...
CVE-2026-5469HIGH7.2A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL ...
CVE-2026-23422HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix interrupt storm after receiving b...
CVE-2026-4350HIGH8.1The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, ...
CVE-2026-35545HIGH8.2An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed...
CVE-2026-35537HIGH7.5An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache sess...
CVE-2026-35535HIGH7.8In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop befor...
CVE-2026-28815HIGH7.5A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulati...
CVE-2026-32211HIGH7.5Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information...
CVE-2026-32173HIGH7.5Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
CVE-2026-26135HIGH8.8Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to ele...
CVE-2026-35467HIGH7.5The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other error...
CVE-2026-34840HIGH8.1OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implem...
CVE-2026-34834HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() ...
CVE-2026-34833HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/ses...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now