2026 CVE Vulnerabilities

55,911 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13072HIGH8.1When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data du...
CVE-2026-13071MEDIUM6.5An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express...
CVE-2026-13070MEDIUM6A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons...
CVE-2026-13069HIGH7.1An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c...
CVE-2026-13068MEDIUM4.3An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac...
CVE-2026-13067HIGH7.2When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be v...
CVE-2026-13066HIGH7.1Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i...
CVE-2026-13065HIGH7.1A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator...
CVE-2026-13064HIGH7.1Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in ...
CVE-2026-13063MEDIUM5.3An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem...
CVE-2026-13062HIGH7.1An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal ...
CVE-2026-13061MEDIUM5.3An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi...
CVE-2026-13060HIGH7.1An authenticated user with limited read privileges may be able to access documents from collections they are not authori...
CVE-2026-13059HIGH8.6An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role...
CVE-2026-13058MEDIUM6.5An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf...
CVE-2026-13057MEDIUM6.5An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In...
CVE-2026-13056HIGH7.1Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object...
CVE-2026-13055HIGH7.1The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)...
CVE-2026-3482MEDIUM5.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6....
CVE-2026-22049HIGH8.8ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnera...
CVE-2026-16624CRITICAL9.6Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on...
CVE-2026-65650MEDIUM4.3Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
CVE-2026-64835HIGH8.8FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within l...
CVE-2026-64834HIGH8.7FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtp...
CVE-2026-64833HIGH7.1FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attacker...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now