2026 CVE Vulnerabilities

64,840 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-28966MEDIUM4.3An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26....
CVE-2026-28937MEDIUM5.5This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be a...
CVE-2026-28934MEDIUM6.5A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoi...
CVE-2026-28933MEDIUM5.5A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS...
CVE-2026-28899MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS...
CVE-2026-28836MEDIUM6.1A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with phy...
CVE-2026-19280MEDIUM5.2IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An auth...
CVE-2026-19273MEDIUM5.4IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gatewa...
CVE-2026-18069MEDIUM6IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a ...
CVE-2026-14277MEDIUM6.3IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal...
CVE-2026-14276MEDIUM6.3IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute ...
CVE-2026-14275MEDIUM6.3IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute ...
CVE-2026-13277MEDIUM4.7IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By ...
CVE-2026-13276MEDIUM6.1IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 ...
CVE-2026-13272MEDIUM5.4IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the...
CVE-2026-12767MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic...
CVE-2026-12766MEDIUM5.4IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat...
CVE-2026-12765MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic...
CVE-2026-12763MEDIUM4.2IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context ...
CVE-2026-90816MEDIUM4.3A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c o...
CVE-2026-90815MEDIUM6.3A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function set...
CVE-2026-90814MEDIUM6.3A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function git...
CVE-2026-90813MEDIUM4.3A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand ...
CVE-2026-73497MEDIUM6.5MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0...
CVE-2026-55244MEDIUM5ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes Bas...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now