2026 CVE Vulnerabilities

56,936 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-64187MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no ...
CVE-2026-58484HIGH7.1Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()`...
CVE-2026-58482MEDIUM5.9Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalI...
CVE-2026-58481MEDIUM6.5Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped fil...
CVE-2026-58414MEDIUM5.5Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recu...
CVE-2026-58413MEDIUM6.1Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, b...
CVE-2026-55645MEDIUM6.5xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client...
CVE-2026-55238MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Co...
CVE-2026-54538HIGH7.5xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to pr...
CVE-2026-54051CRITICAL9.9Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell comma...
CVE-2026-50743MEDIUM5.4A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or ...
CVE-2026-47276MEDIUM6.5In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attac...
CVE-2026-47275LOW2.6In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicio...
CVE-2026-46701HIGH7.6Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an e...
CVE-2026-46555HIGH7.1WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes...
CVE-2026-44978MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the ...
CVE-2026-44178HIGH8.8xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within t...
CVE-2026-42218MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login in...
CVE-2026-42210MEDIUM5.3Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that...
CVE-2026-41521CRITICAL9.1xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing s...
CVE-2026-41252CRITICAL9.8xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap...
CVE-2026-40187HIGH8.6In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) ...
CVE-2026-39879HIGH7.1Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb...
CVE-2026-39385HIGH7.1Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment vali...
CVE-2026-35591HIGH7.8libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now