2026 CVE Vulnerabilities
56,900 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16356 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15... |
| CVE-2026-16355 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115... |
| CVE-2026-16354 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115... |
| CVE-2026-16353 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38... |
| CVE-2026-16352 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15... |
| CVE-2026-16351 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Fire... |
| CVE-2026-16350 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ... |
| CVE-2026-16349 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115... |
| CVE-2026-65009 | MEDIUM | 5.3 | 0.2% | Jul 21, 2026 | OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th... |
| CVE-2026-65008 | CRITICAL | 9.8 | 0.6% | Jul 21, 2026 | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/... |
| CVE-2026-65007 | CRITICAL | 9.6 | 0.3% | Jul 21, 2026 | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the pl... |
| CVE-2026-64628 | MEDIUM | 5.4 | 0.1% | Jul 21, 2026 | Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection s... |
| CVE-2026-64627 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerabilit... |
| CVE-2026-60080 | HIGH | 7.3 | 0.2% | Jul 21, 2026 | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.... |
| CVE-2026-59845 | MEDIUM | 5.9 | 0.1% | Jul 21, 2026 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; durin... |
| CVE-2026-59844 | MEDIUM | 6.5 | 0.5% | Jul 21, 2026 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng... |
| CVE-2026-59843 | MEDIUM | 6.5 | 0.5% | Jul 21, 2026 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN... |
| CVE-2026-59842 | MEDIUM | 5.3 | 0.4% | Jul 21, 2026 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than... |
| CVE-2026-1617 | CRITICAL | 9.8 | — | Jul 21, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communica... |
| CVE-2026-16461 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), v... |
| CVE-2026-64606 | CRITICAL | 9.8 | 0.5% | Jul 21, 2026 | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lamb... |
| CVE-2026-64609 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVa... |
| CVE-2026-64608 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compa... |
| CVE-2026-62415 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membe... |
| CVE-2026-1771 | HIGH | 7.2 | 0.6% | Jul 21, 2026 | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now