2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-74581CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_...
CVE-2026-69502CRITICAL10Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a ne...
CVE-2026-77812CRITICAL9.4DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encry...
CVE-2026-77087CRITICAL9.6Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbit...
CVE-2026-63343CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadat...
CVE-2026-63125CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus...
CVE-2026-62941CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across project...
CVE-2026-62940CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another c...
CVE-2026-62867CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `b...
CVE-2026-48769CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the I...
CVE-2026-48755CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided ba...
CVE-2026-48753CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vuln...
CVE-2026-48752CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance b...
CVE-2026-48751CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restrict...
CVE-2026-48750CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/...
CVE-2026-48749CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used t...
CVE-2026-77806CRITICAL9.8SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August...
CVE-2026-77776CRITICAL9.1Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at...
CVE-2026-59318CRITICAL9.8In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully...
CVE-2026-77683CRITICAL9.9A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the fil...
CVE-2026-77086CRITICAL9.1SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing aut...
CVE-2026-62440CRITICAL9.1Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant mani...
CVE-2026-61398CRITICAL9.1Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password func...
CVE-2026-59085CRITICAL9.1Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery...
CVE-2026-77264CRITICAL9.8The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now