2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-13772CRITICAL9.9IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class nam...
CVE-2026-13449CRITICAL9.1IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE...
CVE-2026-11714CRITICAL9.8IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscover...
CVE-2026-11712CRITICAL9.3IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ...
CVE-2026-11708CRITICAL9.3IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ...
CVE-2026-11546CRITICAL9.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulner...
CVE-2026-10560CRITICAL9.1IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoi...
CVE-2026-10140CRITICAL9.6IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API client...
CVE-2026-10134CRITICAL10IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and...
CVE-2026-10109CRITICAL9.8IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth...
CVE-2026-58138CRITICAL9.8Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote...
CVE-2026-58370CRITICAL9.2Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driv...
CVE-2026-58172CRITICAL9.3Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clie...
CVE-2026-58166CRITICAL9.1OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthentica...
CVE-2026-48315CRITICAL9.3ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-48313CRITICAL9.3ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-48286CRITICAL10Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerabil...
CVE-2026-48283CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne...
CVE-2026-48282CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-48281CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-48277CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-48276CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne...
CVE-2026-14241CRITICAL9.8Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume th...
CVE-2026-8655CRITICAL9.8Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous be...
CVE-2026-8452CRITICAL9.8Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Den...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now