2026 CVEs
139 CVE-2026 IDs the feed has covered, by the month coverage started.
September 2026 73
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2026-88778 TCP Initial Sequence Number (ISN) prediction
- CVE-2026-88777 Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
- CVE-2026-88776 Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
- CVE-2026-88775 Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
- CVE-2026-88774 Feature policy bypass due to improper HTTP URL based expression usage
- CVE-2026-88773 HTTP Request Smuggling
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
- CVE-2026-88761 Botslab G980H Dashcams Use of Weak Credentials
- CVE-2026-85496 Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers
- CVE-2026-84403 Botslab G980H Dashcams Missing Authentication for Critical Function
- CVE-2026-84399 Botslab G980H Dashcams Incorrect Authorization
- CVE-2026-82716 Botslab G980H Dashcams Insertion of Sensitive Information into Log File
- CVE-2026-82566 Botslab G980H Dashcams Insufficient session expiration
- CVE-2026-77967 Botslab G980H Dashcams Authentication Bypass by Capture-replay
- CVE-2026-75558 Botslab G980H Dashcams Use of Hard-coded Cryptographic Key
- CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863)
- CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
- CVE-2026-87902 WordPress WordPress
- CVE-2026-94127 BIG-IP APM OAuth vulnerability
- CVE-2026-93952 Security Advisory 0183
- CVE-2026-93616 Directory Traversal and File upload allows execution of arbitrary script on the Management Server
- CVE-2026-88020 Improper Neutralization of Input During Web Page Generation in OpenPLC Runtime v3
- CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway
- CVE-2026-18963 Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2026-7273 Zyxel GS1900-48HPv2 firmware
- CVE-2026-53266 netfilter: bridge: make ebt_snat ARP rewrite writable
- CVE-2026-76460 Cisco Identity Services Engine Authentication Bypass Vulnerability
- CVE-2026-90894 Parallels Desktop local privilege escalation via appliance extract argument injection
- CVE-2026-58704 Google Android
- CVE-2026-87886 Acronis Acronis Backup plugin for cPanel & WHM
- CVE-2026-88259 CareCam CM2507 Missing Authentication for Critical Function
- CVE-2026-85497 CareCam CM2507 Use of Password Hash With Insufficient Computational Effort
- CVE-2026-85478 CareCam CM2507 Missing Authentication for Critical Function
- CVE-2026-84400 CareCam CM2507 Missing Authentication for Critical Function
- CVE-2026-84398 CareCam CM2507 Empty Password in Configuration File
- CVE-2026-81855 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key
- CVE-2026-81321 CareCam CM2507 Cleartext Storage of Sensitive Information
- CVE-2026-81305 CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere
- CVE-2026-78225 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key
- CVE-2026-68953 Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product Lineups
- CVE-2026-68950 Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups
- CVE-2026-68070 Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product Lineups
- CVE-2026-66890 Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups
- CVE-2026-66887 Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups
- CVE-2026-66372 Predictable Seed in Pseudo-Random Number Generator (PRNG) in Digital Watchdog VMAX DVR and NVR Product Lineups
- CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability
- CVE-2026-85706 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2026-84869 ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
- CVE-2026-42018 Anonymous user token generation exposure in JFrog Artifactory
- CVE-2026-42016 Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
- CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
- CVE-2026-67277 Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
- CVE-2026-20079 Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
- CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability
- CVE-2026-87491 Google Chrome
- CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2026-85083 CareCam Pro IP Cameras Use of Hard-coded Credentials
- CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability
- CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- CVE-2026-86218 pre-authentication remote code execution
- CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2026-9586 Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
- CVE-2026-82329 Potential authentication bypass leading to administrative access in Artifactory
- CVE-2026-59822 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
- CVE-2026-49869 Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
- CVE-2026-48710 Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
- CVE-2026-83549 SonicWall SMA1000
- CVE-2026-83548 SonicWall SMA1000
- CVE-2026-9633 Redundancy Module Configuration Tool - Multiple Vulnerabilities
- CVE-2026-16675 Rockwell Automation FactoryTalk® Activation Manager - Privilege Escalation
- CVE-2026-12661 FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability
August 2026 40
- CVE-2026-77977 Ebyte NA111-M Missing Authentication for Critical Function
- CVE-2026-77975 Ebyte NA111-M Cleartext Storage of Sensitive Information
- CVE-2026-77966 Ebyte NA111-M Missing Authorization
- CVE-2026-76940 Ebyte NA111-M Improper Restriction of Excessive Authentication Attempts
- CVE-2026-76179 Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
- CVE-2026-76133 Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm
- CVE-2026-73125 Ebyte NA111-M Missing Authentication for Critical Function
- CVE-2026-71187 Ebyte NA111-M Use of Client-Side Authentication
- CVE-2026-69658 Ebyte NA111-M Cleartext Transmission of Sensitive Information
- CVE-2026-66384 Authenticated users may write data outside the intended Docker cache path
- CVE-2026-53362 ipv6: account for fraggap on the paged allocation path
- CVE-2026-8452 Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
- CVE-2026-60004 Gitea Gitea
- CVE-2026-21962 Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in
- CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability
- CVE-2026-73570 Zimbra Collaboration
- CVE-2026-19490 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
- CVE-2026-72530 TrueConf TrueConf Server
- CVE-2026-72529 TrueConf TrueConf Server
- CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
- CVE-2026-19478 Improper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability
- CVE-2026-34491 Johnson Controls Metasys 14
- CVE-2026-19188 Haiwell IoT Cloud HMI Gateway OS Command Injection
- CVE-2026-59839 Fortinet FortiProxy
- CVE-2026-23573 Fortinet FortiOS
- CVE-2026-72898 Metabase SQL injection via password reset endpoint
- CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2026-68067 Mira Hormone Monitor, Mira Android App Weak Authentication
- CVE-2026-67568 Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials
- CVE-2026-67558 Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing
- CVE-2026-66875 Mira Hormone Monitor, Mira Android App Missing authentication for critical function
- CVE-2026-66340 Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts
- CVE-2026-66098 Mira Hormone Monitor, Mira Android App Missing authentication for critical function
- CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
- CVE-2026-18844 Pulsetto Vagus Nerve Stimulator Hidden Functionality
- CVE-2026-34486 Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
- CVE-2026-18556 Unauthenticated administrative account takeover
- CVE-2026-18577 Incomplete patch leads to administrative account takeover
- CVE-2026-66066 Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
July 2026 15
- CVE-2026-5846 Hard-coded Cryptographic Key in Watchfire Controllers
- CVE-2026-14227 Insufficient session expiration in MikroTik RouterOS
- CVE-2026-20316 Cisco Secure Firewall Management Center Software Static Credential Vulnerability
- CVE-2026-54429 Siemens SIMATIC S7-PLCSIM Advanced
- CVE-2026-16581 Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application
- CVE-2026-16347 Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router
- CVE-2026-16232 Authentication Bypass in the SmartConsole Login Process Using an Application Token
- CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability
- CVE-2026-9128 Studio 5000 Logix Designer® – Multiple Vulnerabilities
- CVE-2026-9127 Studio 5000 Logix Designer® – Multiple Vulnerabilities
- CVE-2026-9108 Studio 5000 Logix Designer® – Multiple Vulnerabilities
- CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-0770 Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
- CVE-2026-60137 WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
- CVE-2026-15410 SonicWall SMA1000
May 2026 1
- CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability
April 2026 1
- CVE-2026-31431 crypto: algif_aead - Revert to operating out-of-place
March 2026 8
- CVE-2026-21643 Fortinet FortiClientEMS
- CVE-2026-4681 Critical Remote Code Execution vulnerability reported in Windchill
- CVE-2026-3587 Hidden CLI Function Allows Root Access
- CVE-2026-33634 Trivy ecosystem supply chain briefly compromised
- CVE-2026-33017 Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
- CVE-2026-3650 Grassroots DICOM Missing release of memory after effective lifetime
- CVE-2026-2417 Missing Authentication for Critical Function in Pharos Controls Mosaic Show Controller
- CVE-2026-20131 Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
February 2026 1
- CVE-2026-21852 Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation