2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91748 | HIGH | 8.3 | 0.2% | Sep 15, 2026 | Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had comprom... |
| CVE-2026-91745 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2026-91743 | HIGH | 8.3 | 0.2% | Sep 15, 2026 | Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-91741 | HIGH | 8.8 | 0.4% | Sep 15, 2026 | Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary co... |
| CVE-2026-91737 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside... |
| CVE-2026-91736 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside... |
| CVE-2026-91735 | HIGH | 8.3 | 0.3% | Sep 15, 2026 | Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised t... |
| CVE-2026-91734 | HIGH | 7.4 | 0.1% | Sep 15, 2026 | Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execut... |
| CVE-2026-91733 | HIGH | 8.3 | 0.3% | Sep 15, 2026 | Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised ... |
| CVE-2026-91732 | HIGH | 8.1 | 0.2% | Sep 15, 2026 | Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromis... |
| CVE-2026-91731 | HIGH | 8.8 | 0.4% | Sep 15, 2026 | Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary cod... |
| CVE-2026-91727 | HIGH | 8.1 | 0.1% | Sep 15, 2026 | Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker ... |
| CVE-2026-91724 | HIGH | 8.3 | 0.3% | Sep 15, 2026 | Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the render... |
| CVE-2026-91722 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitra... |
| CVE-2026-91721 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arb... |
| CVE-2026-91719 | HIGH | 8.1 | 0.3% | Sep 15, 2026 | Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via ... |
| CVE-2026-91715 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary c... |
| CVE-2026-91712 | HIGH | 8.3 | 0.3% | Sep 15, 2026 | Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had comprom... |
| CVE-2026-91711 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitr... |
| CVE-2026-91709 | HIGH | 8.8 | 0.4% | Sep 15, 2026 | Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary c... |
| CVE-2026-88065 | HIGH | 7.5 | — | Sep 15, 2026 | `tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions ... |
| CVE-2026-79994 | HIGH | 8.7 | 0.1% | Sep 15, 2026 | The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized work... |
| CVE-2026-68950 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providi... |
| CVE-2026-68070 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | The affected products are missing authentication for a critical function, which could allow an attacker to run as root a... |
| CVE-2026-61554 | HIGH | 7.5 | 0.5% | Sep 15, 2026 | emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport acc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now