2026 CVE Vulnerabilities
53,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23457 | HIGH | 8.6 | 0.4% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32... |
| CVE-2026-23456 | HIGH | 8.2 | 0.5% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decod... |
| CVE-2026-23454 | HIGH | 7 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_c... |
| CVE-2026-23453 | HIGH | 7.5 | 0.3% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: Fix memory leak in XDP_DROP ... |
| CVE-2026-23451 | HIGH | 7.5 | 0.4% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_he... |
| CVE-2026-23449 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: Fix double-free in teql_master_xmi... |
| CVE-2026-23448 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes b... |
| CVE-2026-23447 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes b... |
| CVE-2026-23432 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: mshv: Fix use-after-free in mshv_map_user_memory er... |
| CVE-2026-23428 | HIGH | 7.8 | 0.3% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of share_conf in compound... |
| CVE-2026-23427 | HIGH | 7.8 | 0.3% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in durable v2 replay of a... |
| CVE-2026-5469 | HIGH | 7.2 | 0.3% | Apr 3, 2026 | A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL ... |
| CVE-2026-23422 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix interrupt storm after receiving b... |
| CVE-2026-4350 | HIGH | 8.1 | 0.7% | Apr 3, 2026 | The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, ... |
| CVE-2026-35545 | HIGH | 8.2 | 0.3% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed... |
| CVE-2026-35537 | HIGH | 7.5 | 0.5% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache sess... |
| CVE-2026-35535 | HIGH | 7.8 | 0.2% | Apr 3, 2026 | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop befor... |
| CVE-2026-28815 | HIGH | 7.5 | 0.5% | Apr 3, 2026 | A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulati... |
| CVE-2026-32211 | HIGH | 7.5 | 0.8% | Apr 3, 2026 | Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information... |
| CVE-2026-32173 | HIGH | 7.5 | 0.9% | Apr 3, 2026 | Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-26135 | HIGH | 8.8 | 0.6% | Apr 3, 2026 | Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to ele... |
| CVE-2026-35467 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other error... |
| CVE-2026-34840 | HIGH | 8.1 | 0.3% | Apr 2, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implem... |
| CVE-2026-34834 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() ... |
| CVE-2026-34833 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/ses... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now