2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59739 | HIGH | 7.5 | 0.2% | Sep 16, 2026 | Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can dis... |
| CVE-2026-14917 | HIGH | 7.7 | — | Sep 16, 2026 | A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is ... |
| CVE-2026-89792 | HIGH | 7.1 | 0.1% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config ... |
| CVE-2026-89791 | HIGH | 7.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival r... |
| CVE-2026-89789 | HIGH | 7.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error p... |
| CVE-2026-89782 | HIGH | 8.4 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MA... |
| CVE-2026-89781 | HIGH | 8.4 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_bu... |
| CVE-2026-89777 | HIGH | 8.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on ... |
| CVE-2026-89774 | HIGH | 8.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready ... |
| CVE-2026-85501 | HIGH | 7.5 | 0.3% | Sep 16, 2026 | Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. T... |
| CVE-2026-81634 | HIGH | 7.5 | 0.4% | Sep 16, 2026 | In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap b... |
| CVE-2026-80225 | HIGH | 7.5 | 0.3% | Sep 16, 2026 | In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT readin... |
| CVE-2026-73464 | HIGH | 8.8 | 0.5% | Sep 16, 2026 | On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted requ... |
| CVE-2026-73461 | HIGH | 8 | 0.3% | Sep 16, 2026 | On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated us... |
| CVE-2026-73454 | HIGH | 8.1 | 0.3% | Sep 16, 2026 | On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially... |
| CVE-2026-73439 | HIGH | 7.5 | 0.3% | Sep 16, 2026 | On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gN... |
| CVE-2026-2380 | HIGH | 7.4 | 0.2% | Sep 16, 2026 | On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sens... |
| CVE-2026-92355 | HIGH | 8.7 | 0.7% | Sep 16, 2026 | In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a pat... |
| CVE-2026-88263 | HIGH | 8.7 | 0.6% | Sep 16, 2026 | XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve t... |
| CVE-2026-84408 | HIGH | 8.7 | 1.1% | Sep 16, 2026 | QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in... |
| CVE-2026-27564 | HIGH | 7.2 | 2.0% | Sep 16, 2026 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by... |
| CVE-2026-27563 | HIGH | 7.2 | 2.0% | Sep 16, 2026 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by... |
| CVE-2026-27562 | HIGH | 7.2 | 2.2% | Sep 16, 2026 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by send... |
| CVE-2026-27561 | HIGH | 7.2 | 2.2% | Sep 16, 2026 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by send... |
| CVE-2026-27560 | HIGH | 7.2 | 2.2% | Sep 16, 2026 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by send... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now