2026 CVE Vulnerabilities
55,969 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26323 | HIGH | 8.8 | 1.7% | Feb 19, 2026 | OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev ... |
| CVE-2026-26322 | HIGH | 7.6 | 0.3% | Feb 19, 2026 | OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gat... |
| CVE-2026-26321 | HIGH | 7.5 | 0.5% | Feb 19, 2026 | OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendM... |
| CVE-2026-26319 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx ... |
| CVE-2026-21535 | HIGH | 7.5 | 0.6% | Feb 19, 2026 | Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-26317 | HIGH | 7.1 | 0.1% | Feb 19, 2026 | OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin ... |
| CVE-2026-26316 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept w... |
| CVE-2026-26315 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through... |
| CVE-2026-26314 | HIGH | 7.5 | 0.6% | Feb 19, 2026 | go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulne... |
| CVE-2026-26275 | HIGH | 7.5 | 0.2% | Feb 19, 2026 | httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to vers... |
| CVE-2026-27343 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27114 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOf... |
| CVE-2026-26313 | HIGH | 7.5 | 0.6% | Feb 19, 2026 | go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an atta... |
| CVE-2026-26286 | HIGH | 8.5 | 0.3% | Feb 19, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-26318 | HIGH | 8.8 | 1.1% | Feb 19, 2026 | systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command... |
| CVE-2026-26280 | HIGH | 7.8 | 1.2% | Feb 19, 2026 | systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection v... |
| CVE-2026-26278 | HIGH | 7.5 | 0.8% | Feb 19, 2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li... |
| CVE-2026-26267 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` ma... |
| CVE-2026-26205 | HIGH | 7.1 | 0.4% | Feb 19, 2026 | opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability i... |
| CVE-2026-26202 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c... |
| CVE-2026-26201 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are access... |
| CVE-2026-26200 | HIGH | 7.8 | 0.4% | Feb 19, 2026 | HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 c... |
| CVE-2026-26189 | HIGH | 8.1 | 1.3% | Feb 19, 2026 | Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulne... |
| CVE-2026-26063 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attack... |
| CVE-2026-26337 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-s... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now