2026 CVE Vulnerabilities
56,900 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59850 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok... |
| CVE-2026-59849 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clien... |
| CVE-2026-56587 | LOW | 3.7 | 0.2% | Jul 21, 2026 | HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or ma... |
| CVE-2026-56584 | MEDIUM | 5.3 | 0.2% | Jul 21, 2026 | HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software... |
| CVE-2026-47122 | MEDIUM | 4.2 | 0.1% | Jul 21, 2026 | Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `... |
| CVE-2026-46681 | HIGH | 7.2 | 0.3% | Jul 21, 2026 | @nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps fu... |
| CVE-2026-16448 | MEDIUM | 6.3 | — | Jul 21, 2026 | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-32... |
| CVE-2026-15226 | HIGH | 8.4 | — | Jul 21, 2026 | A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler ... |
| CVE-2026-11876 | MEDIUM | 5 | 0.2% | Jul 21, 2026 | In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper ... |
| CVE-2026-9499 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is ... |
| CVE-2026-59848 | MEDIUM | 5.3 | 0.3% | Jul 21, 2026 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep ... |
| CVE-2026-59847 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively re... |
| CVE-2026-47121 | MEDIUM | 6.1 | 0.2% | Jul 21, 2026 | Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `re... |
| CVE-2026-16447 | HIGH | 7.3 | 0.7% | Jul 21, 2026 | A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader... |
| CVE-2026-8285 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces... |
| CVE-2026-8284 | MEDIUM | 6.1 | 0.1% | Jul 21, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data ... |
| CVE-2026-6792 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access ... |
| CVE-2026-59846 | LOW | 3.9 | 0.1% | Jul 21, 2026 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metachara... |
| CVE-2026-16445 | HIGH | 7.5 | 2.9% | Jul 21, 2026 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia... |
| CVE-2026-16412 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruptio... |
| CVE-2026-16411 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2026-16410 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird ... |
| CVE-2026-16409 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16408 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153... |
| CVE-2026-16407 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now