2026 CVE Vulnerabilities
56,936 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64187 | MEDIUM | 5.5 | 0.1% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no ... |
| CVE-2026-58484 | HIGH | 7.1 | 0.1% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()`... |
| CVE-2026-58482 | MEDIUM | 5.9 | 0.1% | Jul 20, 2026 | Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalI... |
| CVE-2026-58481 | MEDIUM | 6.5 | 0.1% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped fil... |
| CVE-2026-58414 | MEDIUM | 5.5 | 0.1% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recu... |
| CVE-2026-58413 | MEDIUM | 6.1 | 0.1% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, b... |
| CVE-2026-55645 | MEDIUM | 6.5 | 0.5% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client... |
| CVE-2026-55238 | MEDIUM | 5.3 | 0.5% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Co... |
| CVE-2026-54538 | HIGH | 7.5 | 0.7% | Jul 20, 2026 | xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to pr... |
| CVE-2026-54051 | CRITICAL | 9.9 | 0.4% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell comma... |
| CVE-2026-50743 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or ... |
| CVE-2026-47276 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attac... |
| CVE-2026-47275 | LOW | 2.6 | 0.2% | Jul 20, 2026 | In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicio... |
| CVE-2026-46701 | HIGH | 7.6 | 0.2% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an e... |
| CVE-2026-46555 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes... |
| CVE-2026-44978 | MEDIUM | 5.3 | 0.5% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the ... |
| CVE-2026-44178 | HIGH | 8.8 | 0.9% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within t... |
| CVE-2026-42218 | MEDIUM | 5.3 | 0.4% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login in... |
| CVE-2026-42210 | MEDIUM | 5.3 | 0.4% | Jul 20, 2026 | Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that... |
| CVE-2026-41521 | CRITICAL | 9.1 | 0.6% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing s... |
| CVE-2026-41252 | CRITICAL | 9.8 | 1.1% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap... |
| CVE-2026-40187 | HIGH | 8.6 | 0.9% | Jul 20, 2026 | In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) ... |
| CVE-2026-39879 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb... |
| CVE-2026-39385 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment vali... |
| CVE-2026-35591 | HIGH | 7.8 | 0.1% | Jul 20, 2026 | libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now