2026 CVE Archive
This archive lists CVEs published in 2026 that have stable human-reviewed guidance or complete source-linked AI enrichment. Open a record for sourced facts, affected-product evidence, and a bounded remediation workflow.
Showing records 1–12 of 12.
- CVE-2026-14956CVE-2026-14956 — Bricksforge Pro Forms privilege escalationCRITICAL · CVSS 9.8 · php/wordpress · Published
- CVE-2026-48027Nx Console Embedded Malicious Code VulnerabilityCRITICAL · CVSS 9.8 · CISA KEV · software/application · Published
- CVE-2026-48172CVE-2026-48172 - LiteSpeed cPanel plugin root privilege escalationCRITICAL · CVSS 10 · CISA KEV · software/application · Published
- CVE-2026-9082CVE-2026-9082 - Drupal core PostgreSQL SQL injectionCRITICAL · CVSS 9.8 · CISA KEV · software/application · Published
- CVE-2026-20182Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityCRITICAL · CVSS 10 · CISA KEV · software/application · Published
- CVE-2026-45321CVE-2026-45321: TanStack npm Supply-Chain RemediationCRITICAL · CVSS 9.6 · CISA KEV · javascript/npm · Published
- CVE-2026-39808Fortinet FortiSandbox OS Command Injection VulnerabilityCRITICAL · CVSS 9.8 · CISA KEV · software/application · Published
- CVE-2026-33116CVE-2026-33116 - .NET System.Security.Cryptography.Xml DoSHIGH · CVSS 7.5 · windows/system · Published
- CVE-2026-39987CVE-2026-39987: Marimo Pre-Auth RCE RemediationCRITICAL · CVSS 9.8 · CISA KEV · python/pypi · Published
- CVE-2026-21643CVE-2026-21643: FortiClient EMS SQL injectionCRITICAL · CVSS 9.8 · CISA KEV · software/application · Published
- CVE-2026-1731BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection VulnerabilityCRITICAL · CVSS 9.9 · CISA KEV · software/application · Published
- CVE-2026-20045Cisco Unified Communications Products Code Injection VulnerabilityCRITICAL · CVSS 9.8 · CISA KEV · software/application · Published