boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, September 16, 2026 · all times UTC← 2026-09-15 · archive

Security Box Score — September 16, 2026

CISA adds 2 to KEV; 871 CVEs published, led by Linux (276).

871 CVEs published September 16, 2026: 85 critical, 382 high, 179 medium, 33 low; 1 in the KEV catalog at press time; 0 with a public exploit reference; 192 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 471 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published878843719——
KEV catalog size1713

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2733 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9074997517235571211230.17.8.0016-354 ▼
microsoft9812880188198269416289301.07.8.0044+539 ▲
google4992665328104111751178090.37.5.0025+450 ▲
red hat1027284330334438200.06.6.0027-40 ▼
apple2465636715226678881.46.5.0019+244 ▲
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.0021-11 ▼
suse1240721111000.07.6.0037+7 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0041+66 ▲
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
f582561441414.08.7.0045+8 ▲
ivanti102410122025520.88.8.0146+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache91602134244193153320.37.5.0048-9 ▼
mozilla11330080100630900.08.8.0025+112 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab17935235510533.25.3.0032+4 ▲
github32011090000.07.3.0044-2 ▼
docker3121830000.08.4.0016+2 ▲
wordpress0513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290358116585631012840.17.8.0034+634 ▲
ibm20782616537027511610.17.5.0029+15 ▲
adobe17177757344366102040.57.5.0023+111 ▲
progress3641539100611.68.1.0035-13 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0099+1 ▲
atlassian3918001300.07.6.0032+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link216619241112300.08.5.0154+5 ▲
siemens1552633103000.07.3.0018-4 ▼
rockwell automation184353260000.08.6.0029+18 ▲
synology02736153000.05.6.0025-1 ▼
advantech172021710000.08.6.0170+17 ▲
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
hitachi energy470340000.06.9.0017+4 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1533242615112720210.37.2.0020+135 ▲
sourcecodester472160012789000.05.5.0027+27 ▲
spring017013608215000.06.5.00240
nvidia3216620117290000.07.8.0029+16 ▲
itsourcecode341500037113000.02.1.0026+23 ▲
mongodb50148487534100.07.1.0026+18 ▲
wwbn1021422247730000.06.9.0024+100 ▲
hewlett packard enterprise (hpe)1291381571466110.77.2.0029+126 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-85706.119695.910.0
CVE-2026-83549.085194.87.8
CVE-2026-82329.076794.39.8
CVE-2026-19586.057092.69.3
CVE-2026-19490.056092.59.3
CVE-2026-79756.051592.08.7
CVE-2026-83548.046791.310.0
CVE-2026-15748.046191.29.8
CVE-2026-77806.042090.49.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.1196KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8782710.0.0107
Most disclosures (vendor)
VendorCVEs
oracle1524
linux1289
microsoft1015
google852
ibm405
apple256
adobe212
dell199
red hat183
mozilla172
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco16
google9
apple8
fortinet7
ivanti5
adobe4
berriai4
jfrog4
oracle4
Most-affected ecosystems
EcosystemAdvisories
Maven93
Packagist39
npm19
PyPI15
RubyGems2
Go1
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-64849mlflow1
CVE-2026-84869ConnectWise2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171764
CVE-2021-27102n/a2021-11-171764
CVE-2021-27101n/a2021-11-171764
CVE-2021-27103n/a2021-11-171764
CVE-2021-21017Adobe2021-11-171764
CVE-2021-28550Adobe2021-11-171764
CVE-2021-42013Apache Software Foundation2021-11-171764
CVE-2021-41773Apache Software Foundation2021-11-171764
CVE-2021-30858Apple2021-11-171764
CVE-2021-30860Apple2021-11-171764

Transactions

ADDED TO KEV — CVE-2026-58704 (Google Android). Remediation due September 19, 2026.

ADDED TO KEV — CVE-2026-76460 (Cisco Identity Services Engine Software). Remediation due September 19, 2026.

EXPLOIT PUBLISHED — grokability snipe-it: 23 CVEs (CVE-2026-85616, CVE-2026-85617, CVE-2026-86754, CVE-2026-86755, CVE-2026-86756, CVE-2026-86757, CVE-2026-86758, CVE-2026-86759, CVE-2026-86760, CVE-2026-86761, CVE-2026-86762, CVE-2026-86763, CVE-2026-86764, CVE-2026-86765, CVE-2026-86766, CVE-2026-86767, CVE-2026-86768, CVE-2026-86769, CVE-2026-86770, CVE-2026-86771, CVE-2026-86772, CVE-2026-86773, CVE-2026-86774). Public exploit references added.

EXPLOIT PUBLISHED — open-webui: 7 CVEs (CVE-2026-87017, CVE-2026-87994, CVE-2026-87995, CVE-2026-87996, CVE-2026-87997, CVE-2026-87998, CVE-2026-87999). Public exploit references added.

EXPLOIT PUBLISHED — gitpython-developers GitPython: 5 CVEs (CVE-2026-67326, CVE-2026-69097, CVE-2026-87817, CVE-2026-87818, CVE-2026-87819). Public exploit references added.

EXPLOIT PUBLISHED — GNU Binutils: 5 CVEs (CVE-2026-90802, CVE-2026-90829, CVE-2026-90831, CVE-2026-91781, CVE-2026-91782). Public exploit references added.

EXPLOIT PUBLISHED — GPAC: 5 CVEs (CVE-2026-90573, CVE-2026-90613, CVE-2026-90685, CVE-2026-90793, CVE-2026-90826). Public exploit references added.

EXPLOIT PUBLISHED — traefik: 5 CVEs (CVE-2026-67309, CVE-2026-85594, CVE-2026-85595, CVE-2026-85596, CVE-2026-85597). Public exploit references added.

EXPLOIT PUBLISHED — PCRE2: 4 CVEs (CVE-2026-89156, CVE-2026-89157, CVE-2026-89160, CVE-2026-89162). Public exploit references added.

EXPLOIT PUBLISHED — tesseract-ocr tesseract: 4 CVEs (CVE-2026-88051, CVE-2026-88052, CVE-2026-88053, CVE-2026-88054). Public exploit references added.

EXPLOIT PUBLISHED — wazuh-manager: 4 CVEs (CVE-2026-74038, CVE-2026-74039, CVE-2026-74044, CVE-2026-74046). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2017-6297. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2020-20211. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2020-20212. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-27168. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-27170. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-27172. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-20079 (Cisco Secure Firewall Management Center (FMC)). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-31278 (supremainc BioStar 2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45186 (libexpat project libexpat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49114 (ONNX). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78155 (OnGres StackGres). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-88765 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-89044 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90496 (Fengoffice Feng Office). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90501 (lenve vhr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90506 (vvbbnn00 WARP-Clash-API). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90511 (GongShengyue OnlineBooks). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90517 (PHPGurukul Bank Locker Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90522 (jaychouchannel Tourism-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90565 (Rizwan17 inventory-management-system). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90575 (PHPGurukul Small CRM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90598 (jaygajera17 E-commerce-project-springBoot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90608 (Totolink A3002MU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90619 (0x4m4 HexStrike AI). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90690 (0x4m4 HexStrike AI). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90695 (SourceCodester Inventory Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90700 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90705 (D-Link DWR-M921). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90710 (taisan tarzan-cms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90716 (marcobambini Gravity). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90788 (magicblack MacCMS10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90807 (nanocoai NanoClaw). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90812 (cosmicstack-labs mercury-agent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90818 (netease-youdao LobsterAI). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90843 (SabyasachiRana WebMap). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90876 (SourceCodester Online Faculty Clearance System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90941 (201206030 novel-plus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91752 (GNU libextractor). Public exploit reference added.

REJECTED — CVE-2026-74259 (Linux). Record withdrawn by the CNA.

RESCORED — Google Android: 17 CVEs (CVE-2026-0129, CVE-2026-0130, CVE-2026-0134, CVE-2026-0136, CVE-2026-0141, CVE-2026-0142, CVE-2026-0144, CVE-2026-0145, CVE-2026-0155, CVE-2026-0158, CVE-2026-0165, CVE-2026-55306, CVE-2026-56888, CVE-2026-56892, CVE-2026-56975, CVE-2026-57008, CVE-2026-58731). CVSS rescored — before/after on each CVE page.

RESCORED — IBM DataStage on Cloud Pak for Data: 6 CVEs (CVE-2026-80378, CVE-2026-80434, CVE-2026-81551, CVE-2026-81554, CVE-2026-82092, CVE-2026-82100). CVSS rescored — before/after on each CVE page.

RESCORED — PCRE2: 5 CVEs (CVE-2026-89156, CVE-2026-89157, CVE-2026-89160, CVE-2026-89161, CVE-2026-89162). CVSS rescored — before/after on each CVE page.

RESCORED — cyrusimap Cyrus IMAP: 4 CVEs (CVE-2026-61908, CVE-2026-61909, CVE-2026-61910, CVE-2026-61915). CVSS rescored — before/after on each CVE page.

RESCORED — Dell ThinOS 10: 3 CVEs (CVE-2026-81048, CVE-2026-81049, CVE-2026-81468). CVSS rescored — before/after on each CVE page.

RESCORED — torproject Tor: 3 CVEs (CVE-2026-77584, CVE-2026-77587, CVE-2026-77638). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-27238 (Adobe InDesign Desktop). CVSS 5.4 → 7.8 (NVD).

RESCORED — CVE-2026-59308 (Spring AI). CVSS 4.2 → 4.3 (NVD).

RESCORED — CVE-2026-59318 (Spring AI). CVSS 6.5 → 9.8 (NVD).

RESCORED — CVE-2026-63523 (Microsoft Skype for Business Server 2015 CU13). CVSS 6.5 → 6.1 (NVD).

RESCORED — CVE-2026-69642 (Microsoft Skype for Business Server 2015 CU13). CVSS 6.5 → 6.1 (NVD).

RESCORED — CVE-2026-69820 (Microsoft Windows 10 Version 21H2). CVSS 8.2 → 6.7 (NVD).

RESCORED — CVE-2026-69832 (Microsoft Windows 10 Version 1607). CVSS 5.6 → 4.7 (NVD).

RESCORED — CVE-2026-69874 (Microsoft Windows 10 Version 1809). CVSS 8.2 → 6.4 (NVD).

RESCORED — CVE-2026-78135 (strongSwan). CVSS 5.6 → 7.3 (NVD).

RESCORED — CVE-2026-83941 (Microsoft Entra). CVSS 9.9 → 8.8 (NVD).

RESCORED — CVE-2026-9336 (IBM WebSphere Application Server). CVSS 6.5 → 7.5 (NVD).

PATCH SHIPPED — Red Hat build of Keycloak 26.6: 20 CVEs (CVE-2026-15945, CVE-2026-16072, CVE-2026-16089, CVE-2026-16093, CVE-2026-16104, CVE-2026-16105, CVE-2026-16106, CVE-2026-16108, CVE-2026-17059, CVE-2026-17615, CVE-2026-18201, CVE-2026-18209, CVE-2026-18214, CVE-2026-18215, CVE-2026-18218, CVE-2026-18570, CVE-2026-18571, CVE-2026-18572, CVE-2026-18573, CVE-2026-79652). Fix versions published.

PATCH SHIPPED — Red Hat Enterprise Linux 10: 4 CVEs (CVE-2026-15709, CVE-2026-15711, CVE-2026-81665, CVE-2026-85197). Fix versions published.

PATCH SHIPPED — CVE-2026-18917 (Red Hat Enterprise Linux 10.0 Extended Update Support). Fixed in Red Hat Enterprise Linux 10.0 Extended Update Support 0:10.10.0-8.12.el10_0.

PATCH SHIPPED — CVE-2026-19729 (Red Hat build of Keycloak 26.4). Fixed in Red Hat build of Keycloak 26.4 26.4.16-2.

ENRICHED — Apple macOS: 20 CVEs (CVE-2026-43789, CVE-2026-43790, CVE-2026-43791, CVE-2026-43815, CVE-2026-65342, CVE-2026-65378, CVE-2026-65381, CVE-2026-65382, CVE-2026-65383, CVE-2026-84522, CVE-2026-84540, CVE-2026-84544, CVE-2026-84548, CVE-2026-84549, CVE-2026-84558, CVE-2026-84565, CVE-2026-84569, CVE-2026-84580, CVE-2026-84584, CVE-2026-84601). Received CVSS/CPE analysis.

ENRICHED — Apple iOS and iPadOS: 3 CVEs (CVE-2026-84533, CVE-2026-84551, CVE-2026-84552). Received CVSS/CPE analysis.

ENRICHED — CVE-2017-17537. Received CVSS 7.5 and CPE data from NVD.

ENRICHED — CVE-2017-6297. Received CVSS 5.9 and CPE data from NVD.

ENRICHED — CVE-2020-20211. Received CVSS 6.5 and CPE data from NVD.

ENRICHED — CVE-2020-20212. Received CVSS 6.5 and CPE data from NVD.

ENRICHED — CVE-2023-27169. Received CVSS 6.5 and CPE data from NVD.

ENRICHED — CVE-2023-27170. Received CVSS 7.5 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

871 CVEs published. 25 box scores and 375 table rows below; the remaining 471 continue on page 2 — every CVE is listed, nothing truncated.

Cisco Identity Services Engine Authentication Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0      —      —   YES
AFFECTED
  Product                                  Versions    Fixed
  Cisco Identity Services Engine Software  3.1.0 p8 –  —
  Cisco ISE Passive Identity Connector     3.4.0 –     —
TIMELINE
  Aug 19  Reserved by CNA
  Sep 16  Added to CISA KEV, due Sep 19
  Sep 16  Published (CNA: cisco)
CWE-648 · CNA: cisco · CVSS v3.1 · 2 references · NVD status: Received · KEV due September 19, 2026
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection via DELETE in /api/status/data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0222   81.8     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection via GET in /api/iodd/config
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0222   81.8     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection via PUT in /api/iodd/config
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0222   81.8     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection in /index.php/ajax/get_iodd_menu_info
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0212   80.9     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection in /index.php/ajax/get_iodd_port_info
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0212   80.9     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection in /index.php/attached_devices_tab/do_upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0212   80.9     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection in Field_Shadow_Password Class
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0212   80.9     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection in /index.php/ajax/parameterManage
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0212   80.9     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection in /index.php/ajax/save_iodd_parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0212   80.9     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0212   80.9     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection via GET in /api/status/data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0212   80.9     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection via GET in /api/datastorage/data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0202   80.0     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Command Injection via PUT in /api/datastorage/data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0202   80.0     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
QualitySoft Corporation QND Premium — QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0107   63.2     —
AFFECTED
  Product       Versions     Fixed
  QND Premium   unspecified  —
  QND Standard  unspecified  —
  QND Advance   unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 16  Published (CNA: jpcert)
CWE-782 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Deferred
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Authentication Bypass in _account_log
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0095   59.6     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-288 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Remote code execution via uploading a malicious IODD file
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0094   59.2     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Local File Inclusion in /index.php/ajax/save_iodd_parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0086   56.7     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-98 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Arista Networks VeloCloud Edge — Security Advisory 0181
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   H   N   H   H   H    7.5   .0083   55.8     —
AFFECTED
  Product         Versions  Fixed
  VeloCloud Edge  6.4.0 –   —
TIMELINE
  Sep 5   Reserved by CNA
  Sep 16  Published (CNA: Arista)
CWE-78 · CNA: Arista · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Local File Inclusion in /index.php/ajax/get_iodd_port_info
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0083   55.6     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-98 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Arista Networks EOS — Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    9.4   .0076   53.4     —
AFFECTED
  Product  Versions   Fixed
  EOS      4.30.2F –  —
TIMELINE
  Aug 12  Reserved by CNA
  Sep 16  Published (CNA: Arista)
CWE-78 · CNA: Arista · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Arista Networks EOS — Security Advisory 0174
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0075   53.1     —
AFFECTED
  Product  Versions   Fixed
  EOS      4.36.0F –  —
TIMELINE
  Aug 12  Reserved by CNA
  Sep 16  Published (CNA: Arista)
CWE-94 · CNA: Arista · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Pepperl+Fuchs ICE2-8IOL1-G65L-V1D — Path Traversal in /index.php/view_uploaded_iodd_file
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0071   51.7     —
AFFECTED
  Product               Versions  Fixed
  ICE2-8IOL1-G65L-V1D   1.0.0 –   —
  ICE2-8IOL-G65L-V1D    1.0.0 –   —
  ICE2-8IOL-K45P-RJ45   1.0.0 –   —
  ICE2-8IOL-K45S-RJ45   1.0.0 –   —
  ICE3-8IOL1-G65L-V1D   1.0.0 –   —
  ICE3-8IOL-G65L-V1D    1.0.0 –   —
  ICE3-8IOL-G65L-V1D-Y  1.0.0 –   —
  ICE3-8IOL-K45P-RJ45   1.0.0 –   —
  ICE3-8IOL-K45S-RJ45   1.0.0 –   —
  IOL MA8 PN DI8        1.0.0 –   —
  + 5 more
TIMELINE
  Feb 20  Reserved by CNA
  Sep 16  Published (CNA: CERTVDE)
CWE-35 · CNA: CERTVDE · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Octopus Deploy Octopus Server — In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0068   50.8     —
AFFECTED
  Product         Versions       Fixed
  Octopus Server  2024.1.4131 –  —
TIMELINE
  Sep 16  Reserved by CNA
  Sep 16  Published (CNA: Octopus)
CWE-22 · CNA: Octopus · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
GitLab GitLab — Allocation of Resources Without Limits or Throttling in GitLab
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0064   48.8     —
AFFECTED
  Product  Versions  Fixed
  GitLab   18.4.6 –  —
TIMELINE
  Dec 18  Reserved by CNA
  Sep 16  Published (CNA: GitLab)
CWE-770 · CNA: GitLab · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-11687.548.8GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-780888.846.8contest-galleryContest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-434Contest Gallery <= 32.0.1 - Unauthenticated Arbitrary File Upload via 'baseUr…
CVE-2026-882638.745.2XikeStorSKS8310-8XCWE-306XikeStor Layer3 switches miss authentication for downloading configuration da…
CVE-2026-275528.145.2Pepperl+FuchsICE2-8IOL1-G65L-V1DCWE-863Unauthorized IODD File Upload due to Improper Authorization
CVE-2026-275536.543.9Pepperl+FuchsICE2-8IOL1-G65L-V1DCWE-497Information Disclosure via Schema Path Manipulation
CVE-2026-816429.143.0NLnet LabsUnboundCWE-122Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY
CVE-2026-922206.943.0vllm-projectvLLMCWE-400vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._h…
CVE-2026-920915.941.4Red HatRed Hat Ansible Automation Platform 2CWE-407Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded…
CVE-2026-84628.940.5openmeteropenmeterCWE-89OpenMeter SQL Injection in ClickHouse-backed Meter Definitions
CVE-2026-734648.740.5Arista NetworksEOSCWE-94Security Advisory 0166
CVE-2026-734558.940.0Arista NetworksEOSCWE-130Security Advisory 0173
CVE-2026-86792await38.4Apache Software FoundationApache Airflow Apache Kafka providerCWE-470Apache Airflow Apache Kafka provider: Connection-editor remote code execution…
CVE-2026-922165.337.8a2ui-projecta2uiCWE-601a2ui-project a2ui Binder generic-binder.ts openUrl redirect
CVE-2026-143499.836.1themetechmountTrueBooker – Appointment Booking and Scheduler SystemCWE-862TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User…
CVE-2026-80304.335.1GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-192487.134.7qtqtCWE-674Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impact…
CVE-2026-827178.434.0NLnet LabsUnboundCWE-122CNAME synthesis could lead to heap corruption
CVE-2026-920815.933.3fastifyfastifyCWE-248fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 tra…
CVE-2026-882556.333.1ZenHivemppCWE-1289mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transac…
CVE-2026-891866.333.1ZenHivemppCWE-524mpp writes Payment-Receipt and Cache-Control before the wrapped application r…
CVE-2026-782528.232.9GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-890637.532.9ladelaOnline Scheduling and Appointment Booking System – BooklyCWE-639Online Scheduling and Appointment Booking System <= 28.1 - Insecure Direct Ob…
CVE-2026-127939.832.5jetmonstersJetFormBuilder — Dynamic Blocks Form BuilderCWE-269JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engi…
CVE-2026-922156.931.7a2ui-projecta2uiCWE-918a2ui-project a2ui FileResolver file_resolver.py httpx.get server-side request…
CVE-2026-816347.529.1NLnet LabsUnboundCWE-122Possible heap buffer overflow during DNSSEC canonicalization
CVE-2026-922997.128.1Jitsi@jitsi/electron-sdkCWE-862@jitsi/electron-sdk before 10.0.5 Unauthorized Screen Capture
CVE-2026-797088.527.3GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-892076.926.9SiemensWTV676-HB6035 Web InterfaceCWE-1287A vulnerability has been identified in WTV676-HB6035 Web Interface (All versi…
CVE-2026-734397.726.4Arista NetworksEOSCWE-842Security Advisory 0164
CVE-2026-734456.925.7Arista NetworksEOSCWE-20Security Advisory 0167
CVE-2026-75144.325.6GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-167944.325.6GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-922986.325.4EspoCRMEspoCRMCWE-338EspoCRM through 10.0.8 Weak Token Generation via rand()
CVE-2026-863386.025.2ash-projectashCWE-1220Ash field policies do not filter-nil forbidden calculations and aggregates, e…
CVE-2026-922175.325.0a2ui-projecta2uiCWE-913a2ui-project a2ui Message Parsing message-processor.ts processMessages dynami…
CVE-2026-863414.424.7GitLabGitLabCWE-1280Access Control Check Implemented After Asset is Accessed in GitLab
CVE-2026-38553.124.5GitLabGitLabCWE-99Improper Control of Resource Identifiers ('Resource Injection') in GitLab
CVE-2026-802255.324.1NLnet LabsUnboundCWE-770Possible degradation of service from continuous queries on the same TCP/DoT c…
CVE-2026-855015.324.1NLnet LabsUnboundCWE-770Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC
CVE-2026-196194.723.0GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-734619.422.5Arista NetworksEOSCWE-266Security Advisory 0163
CVE-2026-734548.622.3Arista NetworksEOSCWE-77Security Advisory 0165
CVE-2026-734696.922.0Arista NetworksEOSCWE-863Security Advisory 0176
CVE-2026-165886.522.1wpdirectorykitWP Directory KitCWE-89WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'order_…
CVE-2026-922472.022.1synaptikcmssynaptik-cmsCWE-284synaptikcms synaptik-cms Admin File Manager file-manager.php rename unrestric…
CVE-2026-119845.321.2spacetimeAd Inserter – Ad Manager & AdSense AdsCWE-862Ad Inserter <= 2.8.16 - Missing Authorization to Unauthenticated Header/Foote…
CVE-2026-827205.921.1NLnet LabsUnboundCWE-416Use-after-free in DoH stream cleanup code path
CVE-2024-112226.420.7GitLabGitLabCWE-367Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
CVE-2026-923586.420.6Red HatRed Hat Build of KeycloakCWE-613Keycloak-services: keycloak-services: residual cross-browser account-link pro…
CVE-2026-76550await19.7UnknownWP Import Export Lite—WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path T…
CVE-2026-76551await19.7UnknownWP Import Export Lite—WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function
CVE-2026-778603.719.7NLnet LabsUnboundCWE-675'serve-expired' can bypass Unbound 'wait-limit'
CVE-2026-922212.019.0gedelumbungHospitalManagementCWE-74gedelumbung HospitalManagement app_global_admin_model.php generate_index_pasi…
CVE-2026-782276.518.9NLnet LabsUnboundCWE-416Use-after-free in DoQ stream output buffer on reset re-transmission
CVE-2026-922145.117.6a2ui-projecta2uiCWE-79a2ui-project a2ui a2a-chat-canvas sanitizer-markdown-renderer-service.ts cros…
CVE-2026-864755.317.2UnknownAppointment Hour BookingCWE-20Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass v…
CVE-2026-734402.317.3Arista NetworksEOSCWE-212Security Advisory 0178
CVE-2026-76552await17.1UnknownWP Import Export Lite—WP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remo…
CVE-2026-734687.116.9Arista NetworksEOSCWE-670Security Advisory 0175
CVE-2026-84439await16.7Apache Software FoundationApache ZooKeeperCWE-117Apache ZooKeeper: Audit log injection via unsanitized output from multiple so…
CVE-2026-185957.216.6wp-labWP-Lister Lite for eBayCWE-79WP-Lister Lite for eBay <= 3.8.9 - Unauthenticated Stored Cross-Site Scriptin…
CVE-2026-82310await16.5Apache Software FoundationApache Airflow FAB providerCWE-613Apache Airflow FAB provider: FAB auth manager: deactivated users retain and r…
CVE-2026-23805.116.4Arista NetworksEOSCWE-256Security Advisory 0168
CVE-2026-861097.515.6Arista NetworksVeloCloud EdgeCWE-347Security Advisory 0182
CVE-2026-79993await15.6Apache Software FoundationApache ZooKeeperCWE-862Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthor…
CVE-2026-922135.114.7a2ui-projecta2uiCWE-74a2ui-project a2ui Angular Renderer server-to-client.ts z.any injection
CVE-2026-734366.014.5Arista NetworksEOSCWE-125Security Advisory 0171
CVE-2026-78472await14.1UnknownNi WooCommerce Sales Report—Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated SQLi via 'sort' Parameter
CVE-2026-59206.413.6boldthemesBold Page BuilderCWE-79Bold Page Builder <= 5.9.6 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-185556.113.4wordplusBetter Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsCWE-79Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plu…
CVE-2026-845015.313.4Apache Software FoundationApache ZooKeeperCWE-117Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAu…
CVE-2026-78474await13.4UnknownNi WooCommerce Sales Report—Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data…
CVE-2026-84829await13.4UnknownOptimole—Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter
CVE-2026-86444await13.4UnknownLearnPress—LearnPress < 4.4.7 - Reflected XSS via 'skin' Parameter
CVE-2026-86448await13.4UnknownLearnPress—LearnPress < 4.4.7 - Unauthenticated Order Data Disclosure via lp_download_order
CVE-2026-86465await13.1Apache Software FoundationApache Airflow Akeyless providerCWE-639Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard …
CVE-2026-134075.412.3UnknownRoyal Addons for ElementorCWE-116Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in …
CVE-2026-734387.011.9Arista NetworksEOSCWE-617Security Advisory 0172
CVE-2026-897839.811.4LinuxLinux—xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
CVE-2026-897778.811.4LinuxLinux—vfio/pci: clear vdev->msi_perm after freeing it on init failure
CVE-2026-897897.811.4LinuxLinux—gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free
CVE-2026-89780await11.4LinuxLinux—net: qualcomm: rmnet: restore skb->dev on deaggregated frames
CVE-2026-89784await11.4LinuxLinux—SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6
CVE-2026-897937.811.2LinuxLinux—ublk: clear VM_MAYWRITE on read-only ublk char device mmap
CVE-2026-76186await10.9Apache Software FoundationApache Airflow Keycloak providerCWE-565Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow…
CVE-2026-897789.810.8LinuxLinux—isofs: fix out-of-bounds page array access on empty zisofs block
CVE-2026-897799.110.8LinuxLinux—fs/ntfs3: validate ef->size covers the record's name and value
CVE-2026-897869.110.8LinuxLinux—ext4: fix out-of-bounds read in ext4_read_inline_dir()
CVE-2026-897818.410.8LinuxLinux—fs/ntfs3: fix out-of-bounds read in read_log_rec_buf()
CVE-2026-897828.410.8LinuxLinux—fs/ntfs3: reject restart table growth beyond U16_MAX entries
CVE-2026-119966.410.7codesupplycoAdvanced PopupsCWE-79Advanced Popups <= 1.2.3 - Authenticated (Author+) Stored Cross-Site Scriptin…
CVE-2026-89776await10.8LinuxLinux—vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
CVE-2026-89785await10.8LinuxLinux—fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init
CVE-2026-89787await10.8LinuxLinux—ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()
CVE-2026-76556await10.6UnknownWP Import Export Lite—WP Import Export Lite < 3.9.33 - Authenticated SQLi via Export Filter Rules
CVE-2026-76557await10.6UnknownWP Import Export Lite—WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options
CVE-2026-734636.09.9Arista NetworksEOSCWE-362Security Advisory 0169
CVE-2026-84088await9.9UnknownXpro Addons — 140+ Widgets for Elementor—Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circl…
CVE-2026-86784await9.9UnknownVisualizer—Visualizer < 4.0.8 - Contributor+ Stored XSS via JSON Data Source
CVE-2026-89790await9.8LinuxLinux—ipv6: avoid divide by zero in rt6_multipath_rebalance
CVE-2026-59739await9.6Apache Software FoundationApache ZooKeeperCWE-862Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
CVE-2026-76558await9.5UnknownWP Import Export Lite—WP Import Export Lite < 3.9.33 - Contributor+ Stored DOM XSS via Custom Field…
CVE-2026-76187await9.5Apache Software FoundationApache Airflow Keycloak providerCWE-287Apache Airflow Keycloak provider: Any realm client's credentials mint an Airf…
CVE-2026-76555await9.5UnknownWP Import Export Lite—WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via …
CVE-2026-82311await9.5Apache Software FoundationApache Airflow FAB providerCWE-613Apache Airflow FAB provider: FAB password reset never invalidates sessions: s…
CVE-2026-86462await9.5Apache Software FoundationApache Airflow FAB providerCWE-613Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate dat…
CVE-2026-196402.39.1Arista NetworksEOSCWE-863Security Advisory 0170
CVE-2026-897748.89.0LinuxLinux—Bluetooth: SCO: hold sk properly in sco_conn_ready
CVE-2026-82124await8.9UnknownSchema & Structured Data for WP & AMP—Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Prote…
CVE-2026-86445await8.9UnknownLearnPress—LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_conten…
CVE-2026-86447await8.9UnknownLearnPress—LearnPress < 4.4.7 - Unauthenticated Student Enrollment Disclosure via load_c…
CVE-2026-86449await8.9UnknownLearnPress—LearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST API
CVE-2026-897889.88.8LinuxLinux—ksmbd: fix tree connection use-after-free in smb2_tree_connect()
CVE-2026-897917.88.7LinuxLinux—perf: Fix use-after-free when perf mmap() revival races with the last munmap()
CVE-2026-897927.18.8LinuxLinux—ksmbd: prevent out-of-bounds reads in share config responses
CVE-2026-198574.88.7UnknownFormidable FormsCWE-74Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via […
CVE-2026-897759.38.2LinuxLinux—KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
CVE-2026-76553await8.0UnknownWP Import Export Lite—WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion v…
CVE-2026-85349await8.0UnknownFluentBoards—FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR
CVE-2026-85572await8.0UnknownTutor LMS—Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure
CVE-2026-77702await7.6UnknownEventin—Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token
CVE-2026-82125await7.6UnknownSchema & Structured Data for WP & AMP—Schema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Publi…
CVE-2026-84907await7.6UnknownEventin—Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Paymen…
CVE-2026-85530await7.6UnknownGiveWP—GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitiza…
CVE-2026-87854await7.5UnknownSubscriptions for WooCommerce—Subscriptions for WooCommerce < 2.0.3 - Unauthenticated Subscription Data Dis…
CVE-2026-87896await7.5UnknownRox Appointment Booking—Rox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disclosure via Ag…
CVE-2026-87907await7.5UnknownRox Appointment Booking—Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes Disclosure v…
CVE-2026-74926await7.0UnknownMultiVendorX—MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership …
CVE-2026-76559await7.0UnknownWP Import Export Lite—WP Import Export Lite < 3.9.33 - Admin+ SSRF via Import URL Handling
CVE-2026-82126await7.0UnknownSchema & Structured Data for WP & AMP—Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public P…
CVE-2026-84905await7.0UnknownEventin—Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation
CVE-2026-85569await7.0UnknownTutor LMS—Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST R…
CVE-2026-87828await6.7UnknownSeraphinite Accelerator—Seraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State Up…
CVE-2026-89327await6.5UnknownFluentBoards—FluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by…
CVE-2026-89328await6.5UnknownFluentBoards—FluentBoards < 2.0.15 - Board Member+ Board Membership and Public Access Modi…
CVE-2026-86823await6.2UnknownNewsletter—Newsletter < 9.3.7 - Unauthenticated Open Redirect and Subscriber Token Discl…
CVE-2026-88910await6.2Unknownkboard—KBoard < 6.7 - Unauthenticated Board Media Deletion via IDOR
CVE-2026-734357.05.9Arista NetworksEOSCWE-345Security Advisory 0171
CVE-2026-87959await5.7UnknownWPBot—WPBot 8.7.2 - 8.7.5 - Subscriber+ Claude AI Settings Update
CVE-2026-85131await4.1UnknownWPLP Cookie Consent—WPLP Cookie Consent < 4.4.4 - Arbitrary Post Deletion via CSRF
CVE-2026-849065.34.1UnknownEventinCWE-345Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross…
CVE-2026-86466await3.6Apache Software FoundationApache Airflow FAB providerCWE-346Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience…
CVE-2026-87860await3.5UnknownSubscriptions for WooCommerce—Subscriptions for WooCommerce < 2.0.3 - Subscription Cancellation via CSRF
CVE-2026-734507.03.1Arista NetworksEOSCWE-345Security Advisory 0161
CVE-2026-779554.42.8NLnet LabsUnboundCWE-345Possible ZONEMD verification bypass window
CVE-2026-813266.82.4QualitySoft CorporationQND PremiumCWE-321QND uses a hard-coded cryptographic key, which may allow a local attacker who…
CVE-2026-85641await2.3UnknownFormidable Forms—Formidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated…
CVE-2026-59969await2.2Apache Software FoundationApache ZooKeeperCWE-297Apache ZooKeeper: Improper validation of certificate with host mismatch in FI…
CVE-2026-864436.90.9Fermax Electronica S.A.U.DuoxMeCWE-312Cleartext Storage of Sensitive Information Vulnerability
CVE-2026-856287.00.1Fermax Electronica S.A.U.DuoxMeCWE-319Cleartext Transmission of Sensitive Information in the Pairing Process vulner…
CVE-2026-2013010.0—CiscoCisco Identity Services Engine SoftwareCWE-74Cisco Identity Services Engine Hardening Release - Improper Neutralization Vu…
CVE-2026-2019210.0—CiscoCisco Identity Services Engine SoftwareCWE-284Cisco Identity Services Engine Hardening Release - Access Control Vulnerabili…
CVE-2026-7041610.0—DellObjectScaleCWE-502Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Un…
CVE-2026-7642310.0—CiscoCisco Identity Services Engine SoftwareCWE-290Cisco ISE API Authentication Bypass Vulnerability
CVE-2026-9280810.0—AltiumAltium Enterprise ServerCWE-306Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service …
CVE-2026-202349.9—CiscoCisco Identity Services Engine SoftwareCWE-522Cisco Identity Services Engine Hardening Release - Insuffiencently Protected …
CVE-2026-203079.9—CiscoCisco Identity Services Engine SoftwareCWE-502Cisco Identity Services Engine Remote Code Execution Vulnerability
CVE-2026-203229.9—CiscoCisco Nexus DashboardCWE-284Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Im…
CVE-2026-203249.9—CiscoCisco Secure Firewall Management Center (FMC)CWE-862Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectuti…
CVE-2026-203259.9—CiscoCisco Nexus DashboardCWE-77Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Im…
CVE-2026-203299.9—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-703Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def…
CVE-2026-203309.9—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-707Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def…
CVE-2026-203329.9—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-284Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def…
CVE-2025-599539.8—InternLMlmdeployCWE-502LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call…
CVE-2026-202429.8—CiscoCisco Secure Firewall Management Center (FMC)CWE-502Cisco Secure Firewall Management Center Software Java Deserialization Remote …
CVE-2026-203269.8—CiscoCisco Nexus DashboardCWE-306Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Mi…
CVE-2026-898479.8—LinuxLinux—scsi: qla2xxx: Avoid double completion in async IOCB timeout
CVE-2026-898579.8—LinuxLinux—scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject
CVE-2026-899699.8—LinuxLinux—nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU
CVE-2026-899709.8—LinuxLinux—nvmet-auth: Synchronize timeout work during SQ teardown
CVE-2026-899729.8—LinuxLinux—nvme: add missing SRCU grace period in error path
CVE-2026-899909.8—LinuxLinux—ceph: lock mutex in ceph_mds_check_access()
CVE-2026-900129.8—LinuxLinux—spi: Fix DMA mapping ownership on partial map failure
CVE-2026-900369.8—LinuxLinux—NFSD: Prevent client use-after-free during blocked-lock reaping
CVE-2026-900379.8—LinuxLinux—NFSD: Prevent client use-after-free during close_lru reaping
CVE-2026-900389.8—LinuxLinux—NFSD: Prevent client use-after-free during export state revocation
CVE-2026-900429.8—LinuxLinux—ceph: properly decrypt filenames in vmalloc() buffers
CVE-2026-900489.8—LinuxLinux—fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()
CVE-2026-918439.8—checkpointQuantum Security ManagementCWE-121Stack overflow in login process to the Security Management and Log Servers
CVE-2026-203319.6—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-693Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def…
CVE-2026-774119.5—rabbitmqamqp091-goCWE-754RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integ…
CVE-2026-581469.4—WNCT-Mobile 5G Box IDUCWE-78Unauthorized remote code execution in T-Mobile 5G Box IDU routers
CVE-2026-774059.4—rabbitmqamqp091-goCWE-326RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In UR…
CVE-2026-408559.3—WNCT-Mobile 5G Box IDUCWE-78Command Injection in T-Mobile 5G Box IDU router via ping functionality
CVE-2026-581479.3—WNCT-Mobile 5G Box IDUCWE-78Authorized remote code execution via password change functionality in T-Mobil…
CVE-2026-731729.3—AdvantechEKI-1242IEIMSCWE-78Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special …
CVE-2026-890829.3—HP IncHP AC Print & ScanCWE-94HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitr…
CVE-2026-890839.3—HP IncHP AC Print & ScanCWE-94HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitr…
CVE-2026-899149.3—LinuxLinux—KVM: arm64: Sign-extend VA for range-based TLBI invalidation
CVE-2026-899159.3—LinuxLinux—KVM: arm64: Remove VM-wide VNCR mapping counter
CVE-2026-899169.3—LinuxLinux—KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry
CVE-2026-899189.3—LinuxLinux—KVM: arm64: Correctly handle end of VA space TLBI invalidation
CVE-2026-899309.3—LinuxLinux—KVM: nVMX: Service local TLB flushes on failed nested VM-Enter
CVE-2026-900499.3—LinuxLinux—net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()
CVE-2026-911049.3—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-122HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-911069.3—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-122HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-927179.3—cobbrCovenantCWE-306Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub
CVE-2026-927209.3—kubero-devkuberoCWE-306Kubero through 3.1.1 Unauthenticated Notifications API Access
CVE-2026-927879.3—feast-devfeastCWE-798Feast through 0.66.0 Authentication Bypass via Unverified Token
CVE-2026-928059.3—uvdeskcommunity-skeletonCWE-306UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Install…
CVE-2026-734569.2—Arista NetworksEOSCWE-94Under certain circumstances, an unauthenticated gNPSI client can craft a mali…
CVE-2026-925769.2—HKUDSnanobotCWE-918HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool
CVE-2026-925789.2—WWBNAVideoCWE-287WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash
CVE-2026-927499.2—chaitinSafeLineCWE-338SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret
CVE-2026-927859.2—Angel-MLangelCWE-502Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes
CVE-2026-201769.1—CiscoCisco Identity Services Engine SoftwareCWE-77Cisco Identity Services Engine Remote Code Execution Vulnerability
CVE-2026-201949.1—CiscoCisco Identity Services Engine SoftwareCWE-669Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfe…
CVE-2026-202119.1—CiscoCisco Identity Services Engine SoftwareCWE-502Cisco Identity Services Engine Remote Code Execution Vulnerability
CVE-2026-202379.1—CiscoCisco Identity Services Engine SoftwareCWE-20Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabi…
CVE-2026-202849.1—CiscoCisco Identity Services Engine SoftwareCWE-943Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability
CVE-2026-203059.1—CiscoCisco Identity Services Engine SoftwareCWE-78Cisco Identity Services Engine Command Injection Vulnerability
CVE-2026-203069.1—CiscoCisco Identity Services Engine SoftwareCWE-78Cisco Identity Services Engine Command Injection Vulnerability
CVE-2026-203419.1—CiscoCisco Secure Firewall Management Center (FMC)CWE-502Cisco Secure Firewall Management Center Software sftunnel Deserialization Roo…
CVE-2026-615949.1—djust-orgdjustCWE-306djust has an authorization bypass on the WebSocket/SSE mount path
CVE-2026-755139.1—JasperFxmartenCWE-89Marten: SQL injection in Marten's LINQ provider via unescaped string literals
CVE-2026-774089.1—rabbitmqamqp091-goCWE-190RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr…
CVE-2026-898469.1—LinuxLinux—scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read
CVE-2026-900119.1—LinuxLinux—scsi: target: iscsi: Reserve a terminator byte for the login payload
CVE-2026-923959.1—@fastify/proxy-addr@fastify/proxy-addrCWE-290@fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
CVE-2026-764209.0—CiscoCisco Secure Firewall Management Center (FMC)CWE-285Cisco Secure Firewall Management Center Software Impersonated sftunnel Connec…
CVE-2026-774038.9—rabbitmqamqp091-goCWE-770RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation
CVE-2026-774108.9—rabbitmqamqp091-goCWE-789RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allo…
CVE-2026-774128.9—rabbitmqamqp091-goCWE-681RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
CVE-2026-203338.8—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-697Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def…
CVE-2026-203368.8—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-664Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def…
CVE-2026-203408.8—CiscoCisco Secure Firewall Management Center (FMC)CWE-502Cisco Secure Firewall Management Center Software Deserialization Arbitrary Ro…
CVE-2026-203448.8—CiscoCisco Secure Firewall Management Center (FMC)CWE-89Cisco Secure Firewall Management Center Software SQL Injection Vulnerability
CVE-2026-203608.8—CiscoCisco Nexus DashboardCWE-200Cisco Nexus Dashboard Software Security Hardening Release September 2026 - In…
CVE-2026-203618.8—CiscoCisco Nexus DashboardCWE-89Cisco Nexus Dashboard Software Security Hardening Release September 2026 - SQ…
CVE-2026-615998.8—djust-orgdjustCWE-470djust has an unauthenticated arbitrary module import via the WebSocket/SSE vi…
CVE-2026-635068.8—tinacmstinacmsCWE-639Tina: [Broken Access Control] letting any TinaCloud user authorize against an…
CVE-2026-731738.8—AdvantechEKI-1242IEIMSCWE-306Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critica…
CVE-2026-764098.8—CiscoCisco Nexus DashboardCWE-22Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Im…
CVE-2026-829648.8—Gen DigitalAvast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business SecurityCWE-281Avast sandbox privilege escalation via unpreserved DACLs on virtualized files…
CVE-2026-848588.8—Scada-LTSScada-LTS—Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass
CVE-2026-848608.8—Scada-LTSScada-LTS—Scada-LTS DWR Authorization Bypass - Systemic
CVE-2026-857318.8—oras-projectoras-goCWE-22oras-go: Arbitrary file write outside file.Store root via symlink-chain bypas…
CVE-2026-868658.8—TaniumAssetCWE-89Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-871058.8—TaniumThreat ResponseCWE-89Tanium addressed a SQL injection vulnerability in Threat Response.
CVE-2026-880648.8—backstagebackstageCWE-20Backstage: Improper input validation in TechDocs MkDocs configuration
CVE-2026-890848.8—HP IncHP AC Print & ScanCWE-22HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitr…
CVE-2026-898048.8—LinuxLinux—drm/nouveau/dmem: fix mismatched DMA unmap size for large folios
CVE-2026-898118.8—LinuxLinux—drm/amdkfd: Add TLB flush after MES queue eviction/suspension
CVE-2026-898448.8—LinuxLinux—scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition
CVE-2026-898498.8—LinuxLinux—scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path
CVE-2026-898608.8—LinuxLinux—scsi: qla2xxx: Initialize NVMe abort_work once at submission
CVE-2026-898988.8—LinuxLinux—media: cec: extron-da-hd-4k-plus: add sanity check
CVE-2026-899078.8—LinuxLinux—LoongArch: KVM: Validate MSI data before routing it to EIOINTC
CVE-2026-899088.8—LinuxLinux—LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY
CVE-2026-899138.8—LinuxLinux—KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables
CVE-2026-899288.8—LinuxLinux—KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk
CVE-2026-899298.8—LinuxLinux—KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU
CVE-2026-899328.8—LinuxLinux—KVM: nVMX: Always flush vpid02 on first use
CVE-2026-899518.8—LinuxLinux—batman-adv: fix stale receive device on merged fragments
CVE-2026-899578.8—LinuxLinux—s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed
CVE-2026-899598.8—LinuxLinux—s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove
CVE-2026-899608.8—LinuxLinux—s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm()
CVE-2026-899958.8—LinuxLinux—dma-direct: return struct page from dma_direct_alloc_from_pool()
CVE-2026-900008.8—LinuxLinux—HID: rmi: fix OOB access with undersized RMI reports
CVE-2026-900188.8—LinuxLinux—staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()
CVE-2026-900418.8—LinuxLinux—HID: sony: clean up device list on probe failure
CVE-2026-921228.8—Jenkins ProjectJenkins Script Security PluginCWE-693Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not che…
CVE-2026-921238.8—Jenkins ProjectJenkins Script Security PluginCWE-693Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not int…
CVE-2026-921248.8—Jenkins ProjectJenkins Script Security PluginCWE-693Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the o…
CVE-2026-921258.8—Jenkins ProjectJenkins Script Security PluginCWE-94Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not rej…
CVE-2026-921378.8—Jenkins ProjectJenkins Robot Framework PluginCWE-22Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the arch…
CVE-2026-925668.8—datageartechdatagearCWE-918DataGear through 6.0.0 Unauthenticated SSRF via HTTP Dataset Preview
CVE-2026-927298.8—SigNozsignozCWE-306SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analyt…
CVE-2026-408548.7—WNCT-Mobile 5G Box IDUCWE-290Session auth bypass via cookie value in T-Mobile 5G Box IDU routers
CVE-2026-470948.7—SIMACMyPHRCWE-639SIMAC MyPHR 1.1 IDOR Account Takeover via /api/employes/put/{id}
CVE-2026-731748.7—AdvantechEKI-1242IEIMSCWE-319Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitiv…
CVE-2026-755168.7—rabbitmqrabbitmq-java-clientCWE-770RabbitMQ Java client: Frame-level OOM: Math.min(maxInboundMessageBodySize, 0)…
CVE-2026-774048.7—rabbitmqamqp091-goCWE-116RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS P…
CVE-2026-824108.7—pocketbasepocketbaseCWE-248Pocketbase: Unhandled panic in worker goroutines
CVE-2026-861068.7—Arista NetworksVeloCloud EdgeCWE-306Security Advisory 0179
CVE-2026-868318.7—AWSaws-network-policy-agentCWE-1289Improper validation of pod identifier uniqueness in aws-network-policy-agent …
CVE-2026-888178.7—Curiosity GmbHCuriosity WorkspaceCWE-269Privilege escalation via legacy access group creation endpoint
CVE-2026-924668.7—zlt2000microservices-platformCWE-862microservices-platform through 6.0.0 Missing Authorization via Disabled URL P…
CVE-2026-924678.7—zlt2000microservices-platformCWE-620microservices-platform through 6.0.0 Unverified Password Change via /users/pa…
CVE-2026-925778.7—WWBNAVideoCWE-639AVideo through 29.0 API get_api_video Broken Access Control via clean_title
CVE-2026-925808.7—WWBNAVideoCWE-78AVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRF
CVE-2026-925928.7—craftcmscmsCWE-1336Craft CMS before 4.18.6 Remote Code Execution via signed cookie
CVE-2026-925938.7—craftcmscmsCWE-94Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution
CVE-2026-925948.7—craftcmscmsCWE-200Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL
CVE-2026-925968.7—nodemailernodemailerCWE-400Nodemailer before 9.1.0 Denial of Service via addressparser
CVE-2026-925998.7—hapijsjoiCWE-1333Joi before 17.13.7 and 18.2.6 ReDoS via isoDate
CVE-2026-927198.7—quickwit-ossquickwitCWE-918Quickwit through 0.9.0 SSRF via SQS queue_url Parameter
CVE-2026-927488.7—BC-SECURITYEmpireCWE-22BC Security Empire before 6.7.1 Path Traversal File Upload RCE
CVE-2026-927528.7—metasfreshmetasfreshCWE-639metasfresh Unauthorized Access via Document Attachments and Comments Endpoints
CVE-2026-927618.7—retspenwebvirtcloudCWE-862WebVirtCloud Missing Authorization on Instance Control Actions
CVE-2026-927628.7—pelicanpanelCWE-862Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup
CVE-2026-927808.7—didiKnowStreamingCWE-862KnowStreaming through 3.4.1 Missing Authorization on the REST API
CVE-2026-927888.7—coze-devcoze-studioCWE-863Coze Studio through 0.5.1 Cross-Tenant Database Access via Workflow SQL Node
CVE-2026-927918.7—uberkrakenCWE-22Uber Kraken through 0.1.29 Path Traversal via tag parameter
CVE-2026-927928.7—OpenNHPopennhpCWE-287OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifier
CVE-2026-927948.7—OpenSignLabsOpenSignCWE-862OpenSign through 2.41.3 Information Disclosure via getDocument
CVE-2026-927968.7—manticoresoftwareManticore SearchCWE-863Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass
CVE-2026-928018.7—chenhg5cc-connectCWE-863cc-connect through 1.5.0 User Allowlist Bypass via Feishu Card Actions
CVE-2026-928158.7—dgtlmoonchangedetection.ioCWE-918changedetection.io through 0.60.6 SSRF via browser-step Goto URL
CVE-2026-195358.6—AdvantechEKI-1242IEIMSCWE-352Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) …
CVE-2026-201358.6—CiscoCisco Secure Firewall Threat Defense (FTD) SoftwareCWE-415Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulne…
CVE-2026-201548.6—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-835Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewal…
CVE-2026-202498.6—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-704Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat …
CVE-2026-202508.6—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-772Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat …
CVE-2026-202958.6—CiscoCisco Secure Firewall Management Center (FMC)CWE-789Cisco Secure Firewall Management Center and Secure Firewall Threat Defense So…
CVE-2026-203528.6—CiscoCisco Identity Services Engine SoftwareCWE-119Cisco Identity Services Engine RADIUS Denial of Service Vulnerability
CVE-2026-731638.6—AdvantechEKI-1242IEIMSCWE-78Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special …
CVE-2026-731648.6—AdvantechEKI-1242IEIMSCWE-78Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special …
CVE-2026-731658.6—AdvantechEKI-1242IEIMSCWE-78Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special …
CVE-2026-731668.6—AdvantechEKI-1242IEIMSCWE-94Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of C…
CVE-2026-731678.6—AdvantechEKI-1242IEIMSCWE-78Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special …
CVE-2026-731708.6—AdvantechEKI-1242IEIMSCWE-94Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of C…
CVE-2026-731718.6—AdvantechEKI-1242IEIMSCWE-73Nozomi Networks Labs identified a CWE-73: External Control of File Name or Pa…
CVE-2026-731768.6—AdvantechEKI-1242IEIMSCWE-78Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special …
CVE-2026-731778.6—AdvantechEKI-1242IEIMSCWE-345Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data …
CVE-2026-910988.6—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-122HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-911058.6—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-122HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-927168.6—ShuffleShuffleCWE-639Shuffle through 2.2.1 API Key Reset Cross-Tenant Privilege Escalation
CVE-2026-927638.6—rundeckrundeckCWE-862Rundeck through 6.2.1 Authorization Bypass via Project Import
CVE-2026-927768.6—requarksWiki.jsCWE-863Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass
CVE-2026-927828.6—chroma-corechromaCWE-863Chroma through 1.5.9 Authorization Bypass via Collection Identifier
CVE-2026-927938.6—GoAdminGroupgo-adminCWE-863GoAdmin through 1.2.26 Authorization Bypass via Query Parameter
CVE-2026-764128.5—CiscoCisco Secure Firewall Management Center (FMC)CWE-264Cisco Secure Firewall Management Center Software Authenticated Privilege Esca…
CVE-2026-863598.5—DellRepository ManagerCWE-276Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Defau…
CVE-2026-923978.5—RuijieRG-EW3000GXCWE-77Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection
CVE-2026-923988.5—RuijieRG-EW3000GXCWE-77Ruijie RG-EW3000GX user_list_note admin os command injection
CVE-2026-927868.5—lightgbm-orgLightGBMCWE-787LightGBM through 4.7.0 Out-of-Bounds Write via Crafted Model
CVE-2026-928168.5—Comfy-OrgComfyUICWE-22ComfyUI before 0.30.0 Path Traversal via dataset save nodes
CVE-2026-203348.4—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-710Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def…
CVE-2026-408578.4—WNCT-Mobile 5G Box IDUCWE-352CSRF token bypass in T-Mobile 5G Box IDU routers
CVE-2026-768258.4—zopefoundationRestrictedPythonCWE-200RestrictedPython: Sandbox escape via string.Formatter field resolution
CVE-2026-897958.4—LinuxLinux—PCI: Allow per function PCI slots to fix slot reset on s390
CVE-2026-898068.4—LinuxLinux—drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation
CVE-2026-898568.4—LinuxLinux—scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation
CVE-2026-898778.4—LinuxLinux—media: saa7164: fix cleanup on resource allocation failure
CVE-2026-898858.4—LinuxLinux—media: platform: mtk-mdp3: Fix SCP device refcounting
CVE-2026-899048.4—LinuxLinux—LoongArch: Fix acpi_package_ids[] array overflow
CVE-2026-899438.4—LinuxLinux—ASoC: loongson: Fix error handling in ACPI property parsing
CVE-2026-899808.4—LinuxLinux—ALSA: harmony: initialize locks before requesting IRQ
CVE-2026-899928.4—LinuxLinux—cpuidle: dt_idle_genpd: kfree() the original name allocation
CVE-2026-911028.4—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-78HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-203238.3—CiscoCisco Secure Firewall Management Center (FMC)CWE-295Cisco Secure Firewall Management Center and Secure Firewall Threat Defense So…
CVE-2026-925978.3—nodemailernodemailerCWE-436Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment
CVE-2026-925988.3—nodemailernodemailerCWE-436Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass
CVE-2026-631278.2—modelcontextprotocolrust-sdkCWE-345RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata …
CVE-2026-711808.2—DellUpdate Package FrameworkCWE-252Dell Update Package Framework, versions prior to 26.07.03, contains an Unchec…
CVE-2026-764138.2—CiscoCisco Secure Firewall Management Center (FMC)CWE-1259Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery…
CVE-2026-774068.2—rabbitmqamqp091-goCWE-195RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer…
CVE-2026-774098.2—rabbitmqamqp091-goCWE-770RabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel Blocking
CVE-2026-861078.2—Arista NetworksVeloCloudCWE-787Security Advisory 0180
CVE-2026-890288.2—MikroTikRouterOSCWE-122MikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndX
CVE-2026-899738.2—LinuxLinux—nvme-tcp: check the data direction of a C2HData PDU
CVE-2026-925918.2—craftcmscmsCWE-636Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer
CVE-2025-439368.1—DellObjectScaleCWE-287Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper…
CVE-2026-203358.1—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-682Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def…
CVE-2026-615918.1—djust-orgdjustCWE-345djust: Unsigned client state snapshot is restored as trusted view state (priv…
CVE-2026-615938.1—djust-orgdjustCWE-352djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a c…
CVE-2026-636718.1—nuxt-contentmdcCWE-79@nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allo…
CVE-2026-749098.1—Red HatRed Hat build of Keycloak 26.4CWE-862Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allow…
CVE-2026-898488.1—LinuxLinux—scsi: qla2xxx: Quiesce response IRQ before freeing request queue
CVE-2026-898618.1—LinuxLinux—scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()
CVE-2026-899998.1—LinuxLinux—HID: wacom: validate report length in wacom_intuos_pro2_bt_irq
CVE-2026-920878.1—@fastify/auth@fastify/authCWE-285@fastify/auth vulnerable to Authorization Bypass via order-dependent evaluati…
CVE-2026-854698.0—Red HatRed Hat Quay 3CWE-1357Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party actio…
CVE-2026-899478.0—LinuxLinux—clk: meson: align gxbb_32k_clk_sel number of parents with actual count
CVE-2026-899548.0—LinuxLinux—mtd: afs: validate v2 image info bounds
CVE-2026-921278.0—Jenkins ProjectJenkins Script Security PluginCWE-94Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automaticall…
CVE-2026-921348.0—Jenkins ProjectJenkins Warnings PluginCWE-79Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not valida…
CVE-2026-921358.0—Jenkins ProjectJenkins Coverage PluginCWE-79Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate th…
CVE-2026-921368.0—Jenkins ProjectJenkins OWASP Dependency-Check PluginCWE-79Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE v…
CVE-2026-899117.9—LinuxLinux—KVM: arm64: Correctly cap TLBI Range to the architural limit
CVE-2026-599747.8—stanfordnlpstanzaCWE-22Stanza: Zip Slip Path Traversal in Model/Resource Extraction
CVE-2026-633257.8—Redoclyredocly-cliCWE-94Redocly CLI: Arbitrary code execution via Arazzo `$faker` expression using `r…
CVE-2026-897997.8—LinuxLinux—bpf: Disable preemption in bpf_get_stackid
CVE-2026-898017.8—LinuxLinux—drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE

Results continue: ranks 401–871.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-16 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.