2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18085 | MEDIUM | 5.9 | 0.2% | Jul 28, 2026 | An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows A... |
| CVE-2026-8058 | MEDIUM | 4.5 | — | Jul 28, 2026 | IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resou... |
| CVE-2026-7868 | MEDIUM | 6.5 | — | Jul 28, 2026 | IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges an... |
| CVE-2026-7775 | MEDIUM | 4.8 | 0.2% | Jul 28, 2026 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM St... |
| CVE-2026-67181 | MEDIUM | 5.4 | 0.3% | Jul 28, 2026 | Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchroni... |
| CVE-2026-66753 | MEDIUM | 6.3 | 0.2% | Jul 28, 2026 | tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return... |
| CVE-2026-66752 | MEDIUM | 6.3 | 0.2% | Jul 28, 2026 | tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize ... |
| CVE-2026-66751 | MEDIUM | 5.4 | 0.2% | Jul 28, 2026 | Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to ar... |
| CVE-2026-66750 | MEDIUM | 5.3 | 0.3% | Jul 28, 2026 | Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to dow... |
| CVE-2026-66746 | MEDIUM | 5.4 | 0.2% | Jul 28, 2026 | Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arb... |
| CVE-2026-62828 | MEDIUM | 5.4 | 0.2% | Jul 28, 2026 | Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a netw... |
| CVE-2026-7521 | MEDIUM | 5.5 | 0.3% | Jul 28, 2026 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deleti... |
| CVE-2026-67173 | MEDIUM | 5.1 | 0.3% | Jul 28, 2026 | Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG i... |
| CVE-2026-66922 | MEDIUM | 5.1 | 0.3% | Jul 28, 2026 | Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-... |
| CVE-2026-66921 | MEDIUM | 6.3 | 0.3% | Jul 28, 2026 | Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpol... |
| CVE-2026-61487 | MEDIUM | 6.5 | 0.4% | Jul 28, 2026 | Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated... |
| CVE-2026-66919 | MEDIUM | 6.9 | 0.3% | Jul 28, 2026 | Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions... |
| CVE-2026-66913 | MEDIUM | 6.9 | 0.3% | Jul 28, 2026 | Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An atta... |
| CVE-2026-65882 | MEDIUM | 6.1 | — | Jul 28, 2026 | Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle w... |
| CVE-2026-62436 | MEDIUM | 6.5 | — | Jul 28, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-62435 | MEDIUM | 6.5 | — | Jul 28, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-62434 | MEDIUM | 5.3 | — | Jul 28, 2026 | A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. Thi... |
| CVE-2026-62429 | MEDIUM | 6.5 | — | Jul 28, 2026 | Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cl... |
| CVE-2026-62425 | MEDIUM | 5.5 | — | Jul 28, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-62424 | MEDIUM | 5.5 | — | Jul 28, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now