2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13772 | CRITICAL | 9.9 | 0.3% | Jun 30, 2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class nam... |
| CVE-2026-13449 | CRITICAL | 9.1 | 0.4% | Jun 30, 2026 | IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE... |
| CVE-2026-11714 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscover... |
| CVE-2026-11712 | CRITICAL | 9.3 | 0.2% | Jun 30, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ... |
| CVE-2026-11708 | CRITICAL | 9.3 | 0.2% | Jun 30, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ... |
| CVE-2026-11546 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulner... |
| CVE-2026-10560 | CRITICAL | 9.1 | 0.3% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoi... |
| CVE-2026-10140 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API client... |
| CVE-2026-10134 | CRITICAL | 10 | 0.3% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and... |
| CVE-2026-10109 | CRITICAL | 9.8 | 0.9% | Jun 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth... |
| CVE-2026-58138 | CRITICAL | 9.8 | 0.9% | Jun 30, 2026 | Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote... |
| CVE-2026-58370 | CRITICAL | 9.2 | 0.5% | Jun 30, 2026 | Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driv... |
| CVE-2026-58172 | CRITICAL | 9.3 | 0.4% | Jun 30, 2026 | Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clie... |
| CVE-2026-58166 | CRITICAL | 9.1 | 0.6% | Jun 30, 2026 | OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthentica... |
| CVE-2026-48315 | CRITICAL | 9.3 | — | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re... |
| CVE-2026-48313 | CRITICAL | 9.3 | — | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir... |
| CVE-2026-48286 | CRITICAL | 10 | 0.7% | Jun 30, 2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerabil... |
| CVE-2026-48283 | CRITICAL | 10 | — | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne... |
| CVE-2026-48282 | CRITICAL | 10 | 3.2% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir... |
| CVE-2026-48281 | CRITICAL | 10 | — | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re... |
| CVE-2026-48277 | CRITICAL | 10 | 0.9% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re... |
| CVE-2026-48276 | CRITICAL | 10 | 0.9% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne... |
| CVE-2026-14241 | CRITICAL | 9.8 | 0.3% | Jun 30, 2026 | Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume th... |
| CVE-2026-8655 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous be... |
| CVE-2026-8452 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Den... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now