2026 CVE Vulnerabilities
64,840 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28966 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.... |
| CVE-2026-28937 | MEDIUM | 5.5 | 0.1% | Sep 14, 2026 | This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be a... |
| CVE-2026-28934 | MEDIUM | 6.5 | 0.2% | Sep 14, 2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoi... |
| CVE-2026-28933 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS... |
| CVE-2026-28899 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS... |
| CVE-2026-28836 | MEDIUM | 6.1 | 0.2% | Sep 14, 2026 | A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with phy... |
| CVE-2026-19280 | MEDIUM | 5.2 | 0.1% | Sep 14, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An auth... |
| CVE-2026-19273 | MEDIUM | 5.4 | 0.3% | Sep 14, 2026 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gatewa... |
| CVE-2026-18069 | MEDIUM | 6 | 0.1% | Sep 14, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a ... |
| CVE-2026-14277 | MEDIUM | 6.3 | 0.5% | Sep 14, 2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal... |
| CVE-2026-14276 | MEDIUM | 6.3 | 0.3% | Sep 14, 2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute ... |
| CVE-2026-14275 | MEDIUM | 6.3 | 0.3% | Sep 14, 2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute ... |
| CVE-2026-13277 | MEDIUM | 4.7 | 0.3% | Sep 14, 2026 | IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By ... |
| CVE-2026-13276 | MEDIUM | 6.1 | 0.2% | Sep 14, 2026 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 ... |
| CVE-2026-13272 | MEDIUM | 5.4 | 0.1% | Sep 14, 2026 | IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the... |
| CVE-2026-12767 | MEDIUM | 6.5 | 0.2% | Sep 14, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic... |
| CVE-2026-12766 | MEDIUM | 5.4 | 0.2% | Sep 14, 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat... |
| CVE-2026-12765 | MEDIUM | 6.5 | 0.2% | Sep 14, 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic... |
| CVE-2026-12763 | MEDIUM | 4.2 | 0.1% | Sep 14, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context ... |
| CVE-2026-90816 | MEDIUM | 4.3 | 0.4% | Sep 14, 2026 | A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c o... |
| CVE-2026-90815 | MEDIUM | 6.3 | 0.2% | Sep 14, 2026 | A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function set... |
| CVE-2026-90814 | MEDIUM | 6.3 | — | Sep 14, 2026 | A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function git... |
| CVE-2026-90813 | MEDIUM | 4.3 | — | Sep 14, 2026 | A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand ... |
| CVE-2026-73497 | MEDIUM | 6.5 | — | Sep 14, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0... |
| CVE-2026-55244 | MEDIUM | 5 | 0.2% | Sep 14, 2026 | ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes Bas... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now