2026 CVE Vulnerabilities
64,732 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79916 | CRITICAL | 9.1 | 0.3% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject con... |
| CVE-2026-77521 | CRITICAL | 10 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skil... |
| CVE-2026-67827 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote C... |
| CVE-2026-46649 | CRITICAL | 9.1 | 0.4% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-58491 | CRITICAL | 9.3 | 0.5% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/provider... |
| CVE-2026-93012 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a... |
| CVE-2026-79920 | CRITICAL | 9.9 | 0.6% | Sep 21, 2026 | Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/t... |
| CVE-2026-61674 | CRITICAL | 9.2 | 0.9% | Sep 21, 2026 | Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0... |
| CVE-2026-85751 | CRITICAL | 9.8 | 1.1% | Sep 21, 2026 | Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-ch... |
| CVE-2026-36469 | CRITICAL | 9.1 | 0.2% | Sep 21, 2026 | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Medi... |
| CVE-2026-94301 | CRITICAL | 9.8 | — | Sep 21, 2026 | The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.ref... |
| CVE-2026-86473 | CRITICAL | 9.1 | 0.5% | Sep 21, 2026 | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client ... |
| CVE-2026-82187 | CRITICAL | 9.8 | 0.1% | Sep 21, 2026 | The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded file... |
| CVE-2026-94101 | CRITICAL | 9.9 | — | Sep 21, 2026 | A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function v... |
| CVE-2026-94100 | CRITICAL | 9.9 | 0.5% | Sep 21, 2026 | A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of th... |
| CVE-2026-94099 | CRITICAL | 9.9 | 1.7% | Sep 21, 2026 | A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of... |
| CVE-2026-94098 | CRITICAL | 9.1 | 2.4% | Sep 21, 2026 | A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the fil... |
| CVE-2026-94097 | CRITICAL | 10 | 2.0% | Sep 21, 2026 | A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-... |
| CVE-2026-94096 | CRITICAL | 9.9 | — | Sep 21, 2026 | A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of... |
| CVE-2026-94095 | CRITICAL | 9.9 | 1.7% | Sep 21, 2026 | A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown funct... |
| CVE-2026-94089 | CRITICAL | 10 | 1.0% | Sep 20, 2026 | A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_aut... |
| CVE-2026-88857 | CRITICAL | 9.4 | 0.5% | Sep 20, 2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension f... |
| CVE-2026-88856 | CRITICAL | 9.4 | 0.5% | Sep 20, 2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension f... |
| CVE-2026-88854 | CRITICAL | 9.3 | 0.3% | Sep 20, 2026 | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 ... |
| CVE-2026-90817 | CRITICAL | 9.8 | 0.6% | Sep 20, 2026 | An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import proce... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now