2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-59739HIGH7.5Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can dis...
CVE-2026-14917HIGH7.7A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is ...
CVE-2026-89792HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config ...
CVE-2026-89791HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival r...
CVE-2026-89789HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error p...
CVE-2026-89782HIGH8.4In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MA...
CVE-2026-89781HIGH8.4In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_bu...
CVE-2026-89777HIGH8.8In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on ...
CVE-2026-89774HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready ...
CVE-2026-85501HIGH7.5Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. T...
CVE-2026-81634HIGH7.5In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap b...
CVE-2026-80225HIGH7.5In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT readin...
CVE-2026-73464HIGH8.8On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted requ...
CVE-2026-73461HIGH8On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated us...
CVE-2026-73454HIGH8.1On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially...
CVE-2026-73439HIGH7.5On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gN...
CVE-2026-2380HIGH7.4On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sens...
CVE-2026-92355HIGH8.7In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a pat...
CVE-2026-88263HIGH8.7XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve t...
CVE-2026-84408HIGH8.7QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in...
CVE-2026-27564HIGH7.2A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by...
CVE-2026-27563HIGH7.2A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by...
CVE-2026-27562HIGH7.2A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by send...
CVE-2026-27561HIGH7.2A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by send...
CVE-2026-27560HIGH7.2A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by send...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now