2026 CVE Vulnerabilities

55,566 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44909HIGH7.5Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate...
CVE-2026-16768MEDIUM5.3A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale...
CVE-2026-65917HIGH8.8CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in ...
CVE-2026-65916HIGH8.1CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCre...
CVE-2026-48539MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf...
CVE-2026-48538MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat...
CVE-2026-48537MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati...
CVE-2026-48536MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio...
CVE-2026-48535MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati...
CVE-2026-48534MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that all...
CVE-2026-48533Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-48532MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy conf...
CVE-2026-48531MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration tha...
CVE-2026-48530MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration...
CVE-2026-16584HIGH7.3Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to ...
CVE-2026-15617CRITICAL9.1Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unaut...
CVE-2026-15616CRITICAL9.1Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirem...
CVE-2026-15615HIGH7.5Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and ...
CVE-2026-15614HIGH7.5Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid...
CVE-2026-15612CRITICAL9.1Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication...
CVE-2026-15611CRITICAL9.1Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive Id...
CVE-2026-11804MEDIUM5.2Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux...
CVE-2026-43823HIGH7.5When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the c...
CVE-2026-43820HIGH7.7NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to...
CVE-2026-8287MEDIUM4.3Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now