2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53625 | HIGH | 7.5 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate... |
| CVE-2026-53610 | HIGH | 7.5 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a das... |
| CVE-2026-49470 | HIGH | 7.7 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password veri... |
| CVE-2026-47679 | HIGH | 8.5 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user c... |
| CVE-2026-97885 | HIGH | 7.3 | — | Sep 25, 2026 | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affecte... |
| CVE-2026-97883 | HIGH | 7.3 | — | Sep 25, 2026 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db... |
| CVE-2026-97882 | HIGH | 7.3 | — | Sep 25, 2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-91841 | HIGH | 7.8 | — | Sep 25, 2026 | A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vul... |
| CVE-2026-91840 | HIGH | 7.8 | — | Sep 25, 2026 | A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to r... |
| CVE-2026-91839 | HIGH | 7.8 | — | Sep 25, 2026 | A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service im... |
| CVE-2026-91838 | HIGH | 7.8 | — | Sep 25, 2026 | A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit t... |
| CVE-2026-84462 | HIGH | 8.6 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zamm... |
| CVE-2026-61525 | HIGH | 8.8 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for ... |
| CVE-2026-56733 | HIGH | 8.7 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack... |
| CVE-2026-56731 | HIGH | 8.4 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user m... |
| CVE-2026-56727 | HIGH | 7.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP emai... |
| CVE-2026-56725 | HIGH | 8.7 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request t... |
| CVE-2026-97878 | HIGH | 7.3 | — | Sep 25, 2026 | A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /d... |
| CVE-2026-97877 | HIGH | 7.3 | — | Sep 25, 2026 | A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.... |
| CVE-2026-97871 | HIGH | 7.3 | — | Sep 25, 2026 | A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of ... |
| CVE-2026-94445 | HIGH | 8.8 | — | Sep 25, 2026 | A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's truste... |
| CVE-2026-91837 | HIGH | 7.8 | — | Sep 25, 2026 | A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can explo... |
| CVE-2026-89032 | HIGH | 7.7 | — | Sep 25, 2026 | BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that al... |
| CVE-2026-67419 | HIGH | 7.1 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exch... |
| CVE-2026-67410 | HIGH | 8.2 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed via Unauthe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now