2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14986 | MEDIUM | 6.8 | 0.2% | Sep 14, 2026 | The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGE... |
| CVE-2026-91181 | MEDIUM | 6.5 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team obje... |
| CVE-2026-91146 | MEDIUM | 6.1 | 0.2% | Sep 14, 2026 | Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, a... |
| CVE-2026-90828 | MEDIUM | 6.6 | 0.2% | Sep 14, 2026 | A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible ... |
| CVE-2026-76081 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permission... |
| CVE-2026-73449 | MEDIUM | 5.9 | 0.1% | Sep 14, 2026 | On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured wi... |
| CVE-2026-13265 | MEDIUM | 6.8 | 0.2% | Sep 14, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1... |
| CVE-2026-12759 | MEDIUM | 6.5 | 0.4% | Sep 14, 2026 | IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled... |
| CVE-2026-12758 | MEDIUM | 5.4 | 0.3% | Sep 14, 2026 | IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoi... |
| CVE-2026-90820 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function Authorizat... |
| CVE-2026-90818 | MEDIUM | 4.3 | 0.5% | Sep 14, 2026 | A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the f... |
| CVE-2026-86924 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7,... |
| CVE-2026-86911 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app ma... |
| CVE-2026-86910 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequ... |
| CVE-2026-86909 | MEDIUM | 4.4 | 0.2% | Sep 14, 2026 | A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be a... |
| CVE-2026-86905 | MEDIUM | 5.5 | 0.1% | Sep 14, 2026 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate... |
| CVE-2026-86903 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS G... |
| CVE-2026-86902 | MEDIUM | 5.5 | 0.1% | Sep 14, 2026 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2026-86900 | MEDIUM | 6.5 | 0.2% | Sep 14, 2026 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. M... |
| CVE-2026-86898 | MEDIUM | 5.4 | 0.1% | Sep 14, 2026 | A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macO... |
| CVE-2026-86897 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7,... |
| CVE-2026-86892 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and... |
| CVE-2026-86890 | MEDIUM | 4.6 | 0.2% | Sep 14, 2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27.... |
| CVE-2026-86889 | MEDIUM | 4.8 | 0.1% | Sep 14, 2026 | A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden G... |
| CVE-2026-86886 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iO... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now