2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92125 | HIGH | 8.8 | 0.5% | Sep 16, 2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annot... |
| CVE-2026-92124 | HIGH | 8.8 | 0.6% | Sep 16, 2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elem... |
| CVE-2026-92123 | HIGH | 8.8 | 0.6% | Sep 16, 2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null recei... |
| CVE-2026-92122 | HIGH | 8.8 | 0.6% | Sep 16, 2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy crea... |
| CVE-2026-89028 | HIGH | 7.5 | 0.6% | Sep 16, 2026 | MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows re... |
| CVE-2026-81736 | HIGH | 7.5 | — | Sep 16, 2026 | If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the... |
| CVE-2026-81563 | HIGH | 7.5 | — | Sep 16, 2026 | A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fa... |
| CVE-2026-77692 | HIGH | 7.5 | — | Sep 16, 2026 | An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(... |
| CVE-2026-73177 | HIGH | 8.6 | — | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware ... |
| CVE-2026-61598 | HIGH | 7.1 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-61590 | HIGH | 7.4 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-19667 | HIGH | 7.5 | — | Sep 16, 2026 | If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in... |
| CVE-2026-88817 | HIGH | 8.7 | 0.3% | Sep 16, 2026 | An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an exi... |
| CVE-2026-73176 | HIGH | 8.6 | 1.0% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-73175 | HIGH | 7.1 | 0.2% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway compone... |
| CVE-2026-73174 | HIGH | 8.7 | 0.1% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserve... |
| CVE-2026-73173 | HIGH | 8.8 | 0.7% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver m... |
| CVE-2026-73171 | HIGH | 8.6 | 0.5% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore work... |
| CVE-2026-73170 | HIGH | 8.6 | 0.5% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the... |
| CVE-2026-73167 | HIGH | 8.6 | 1.0% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-73166 | HIGH | 8.6 | 0.7% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the... |
| CVE-2026-73165 | HIGH | 8.6 | 1.0% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-73164 | HIGH | 8.6 | 0.9% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-73163 | HIGH | 8.6 | 0.9% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-19535 | HIGH | 8.6 | 0.2% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative we... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now