2026 CVE Vulnerabilities
64,732 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50608 | LOW | 1.2 | — | Sep 17, 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. ... |
| CVE-2026-50607 | LOW | 2.7 | — | Sep 17, 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. ... |
| CVE-2026-50606 | LOW | 1.2 | — | Sep 17, 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. ... |
| CVE-2026-91017 | LOW | 3.7 | — | Sep 17, 2026 | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming... |
| CVE-2026-91008 | LOW | 3.7 | — | Sep 17, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization ... |
| CVE-2026-87836 | LOW | 2.7 | — | Sep 17, 2026 | The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderat... |
| CVE-2026-86446 | LOW | 3.7 | — | Sep 17, 2026 | The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is c... |
| CVE-2026-20071 | LOW | 3.8 | — | Sep 16, 2026 | A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated... |
| CVE-2026-92474 | LOW | 3.3 | — | Sep 16, 2026 | A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src... |
| CVE-2026-87026 | LOW | 3.8 | — | Sep 16, 2026 | Tanium addressed an improper access controls vulnerability in Threat Response. |
| CVE-2026-81870 | LOW | 2 | — | Sep 16, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider em... |
| CVE-2026-92473 | LOW | 3.3 | — | Sep 16, 2026 | A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src... |
| CVE-2026-92472 | LOW | 3.3 | — | Sep 16, 2026 | A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file... |
| CVE-2026-92418 | LOW | 3.5 | — | Sep 16, 2026 | A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability aff... |
| CVE-2026-86071 | LOW | 3.7 | 0.4% | Sep 16, 2026 | Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/git... |
| CVE-2026-73442 | LOW | 3 | — | Sep 16, 2026 | On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged i... |
| CVE-2026-87031 | LOW | 2.7 | 0.4% | Sep 16, 2026 | n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of co... |
| CVE-2026-69200 | LOW | 3.7 | 0.3% | Sep 16, 2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fiel... |
| CVE-2026-92385 | LOW | 2.4 | 0.4% | Sep 16, 2026 | A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown fun... |
| CVE-2026-92381 | LOW | 3.5 | — | Sep 16, 2026 | A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/... |
| CVE-2026-92130 | LOW | 3.1 | — | Sep 16, 2026 | Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials... |
| CVE-2026-92359 | LOW | 3.1 | 0.2% | Sep 16, 2026 | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_a... |
| CVE-2026-77860 | LOW | 3.7 | 0.3% | Sep 16, 2026 | In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a dou... |
| CVE-2026-3855 | LOW | 3.1 | 0.3% | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and... |
| CVE-2026-89328 | LOW | 3.8 | 0.2% | Sep 16, 2026 | The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges bef... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now