2026 CVE Vulnerabilities
64,732 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67419 | HIGH | 7.1 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exch... |
| CVE-2026-67410 | HIGH | 8.2 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed via Unauthe... |
| CVE-2026-67409 | HIGH | 8.2 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18, JWKS Fetch Ig... |
| CVE-2026-67408 | HIGH | 7.1 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 4.1.0 until 4.3.3, 4.2.9, and 4.1.11, Stream Management Super-Stream ... |
| CVE-2026-67239 | HIGH | 7.6 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3, Store... |
| CVE-2026-67237 | HIGH | 7.5 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a bearer token... |
| CVE-2026-56724 | HIGH | 7.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission che... |
| CVE-2026-56723 | HIGH | 7.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who can view a ticket can... |
| CVE-2026-100248 | HIGH | 8.4 | — | Sep 25, 2026 | The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin. |
| CVE-2026-67236 | HIGH | 8.2 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_autho... |
| CVE-2026-50547 | HIGH | 7.5 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-49850 | HIGH | 7.5 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-44642 | HIGH | 8.1 | — | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_right... |
| CVE-2026-42324 | HIGH | 7.2 | — | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.ph... |
| CVE-2026-42323 | HIGH | 7.2 | — | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php ac... |
| CVE-2026-33639 | HIGH | 7.2 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-96812 | HIGH | 8.8 | — | Sep 25, 2026 | Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73c... |
| CVE-2026-93306 | HIGH | 7.1 | 0.2% | Sep 25, 2026 | IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 ... |
| CVE-2026-84882 | HIGH | 7.5 | — | Sep 25, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload compon... |
| CVE-2026-84862 | HIGH | 7.2 | — | Sep 25, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticat... |
| CVE-2026-97865 | HIGH | 7.3 | — | Sep 25, 2026 | A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of ... |
| CVE-2026-93834 | HIGH | 8.8 | — | Sep 25, 2026 | A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker... |
| CVE-2026-85750 | HIGH | 7.2 | — | Sep 25, 2026 | Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using... |
| CVE-2026-85542 | HIGH | 8.8 | 2.4% | Sep 25, 2026 | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionalit... |
| CVE-2026-85029 | HIGH | 7.5 | — | Sep 25, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now