2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-74581 | CRITICAL | 9.8 | 0.2% | Aug 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_... |
| CVE-2026-69502 | CRITICAL | 10 | 0.6% | Aug 21, 2026 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a ne... |
| CVE-2026-77812 | CRITICAL | 9.4 | 0.1% | Aug 21, 2026 | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encry... |
| CVE-2026-77087 | CRITICAL | 9.6 | 0.6% | Aug 21, 2026 | Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbit... |
| CVE-2026-63343 | CRITICAL | 9.9 | 0.3% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadat... |
| CVE-2026-63125 | CRITICAL | 9.9 | 0.4% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus... |
| CVE-2026-62941 | CRITICAL | 9.9 | 0.2% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across project... |
| CVE-2026-62940 | CRITICAL | 9.9 | 0.2% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another c... |
| CVE-2026-62867 | CRITICAL | 9.9 | 0.3% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `b... |
| CVE-2026-48769 | CRITICAL | 9.9 | 0.4% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the I... |
| CVE-2026-48755 | CRITICAL | 9.9 | 0.4% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided ba... |
| CVE-2026-48753 | CRITICAL | 9.9 | 0.7% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vuln... |
| CVE-2026-48752 | CRITICAL | 9.9 | 0.8% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance b... |
| CVE-2026-48751 | CRITICAL | 9.9 | 0.7% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restrict... |
| CVE-2026-48750 | CRITICAL | 9.9 | 0.8% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/... |
| CVE-2026-48749 | CRITICAL | 9.9 | 0.8% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used t... |
| CVE-2026-77806 | CRITICAL | 9.8 | 4.2% | Aug 21, 2026 | SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August... |
| CVE-2026-77776 | CRITICAL | 9.1 | 0.3% | Aug 21, 2026 | Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at... |
| CVE-2026-59318 | CRITICAL | 9.8 | 0.2% | Aug 21, 2026 | In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully... |
| CVE-2026-77683 | CRITICAL | 9.9 | 1.5% | Aug 21, 2026 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the fil... |
| CVE-2026-77086 | CRITICAL | 9.1 | 0.6% | Aug 21, 2026 | SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing aut... |
| CVE-2026-62440 | CRITICAL | 9.1 | 0.2% | Aug 21, 2026 | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant mani... |
| CVE-2026-61398 | CRITICAL | 9.1 | 0.2% | Aug 21, 2026 | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password func... |
| CVE-2026-59085 | CRITICAL | 9.1 | 0.3% | Aug 21, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery... |
| CVE-2026-77264 | CRITICAL | 9.8 | 0.6% | Aug 21, 2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now