By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 29 of 86
- CVE-2026-38718HIGH 7.5
InHand Networks has released information about a buffer overflow vulnerability affecting IR912 and IR915 industrial routers (version 1.0.0.r20042 and earlier). An unauthenticated attacker on the network can send specially crafted data during device registration that overflows a memory buffer, crashing the device and rendering it unavailable. No authentication or user interaction is required to trigger the issue.
- CVE-2026-38891HIGH 7.5
CVE-2026-38891 is a denial-of-service vulnerability in gazebo_plugins version 3.9.0, specifically in the differential drive controller component. An attacker can crash or hang a ROS-based robot system by sending a specially crafted motion command message. The vulnerability stems from insufficient validation of incoming command data, allowing malformed input to trigger a crash condition. No authentication is required; any network-accessible ROS system running the affected code is at risk.
- CVE-2026-38970HIGH 7.5
pdfcpu, a PDF processing library, has a denial-of-service vulnerability through version 0.11.1. The issue stems from the parser recursively processing nested PDF objects without limits on how deeply it will descend. An attacker can craft a malicious PDF file with excessive nesting to exhaust server memory and crash the application, denying service to legitimate users.
- CVE-2026-38976HIGH 7.5
mrubyc versions up to 3.4.1 contain a critical flaw in how they handle the `super` keyword when used at the top level of code. Normally, `super` calls the parent class's implementation of a method, but when invoked outside a proper method context, the application fails to validate this precondition. This causes the program to attempt to access memory that hasn't been initialized, resulting in a crash. An attacker with network access can trigger this crash remotely without needing credentials or user interaction, making the system unavailable.
- CVE-2026-39007HIGH 7.5
Observeinc's Observe platform versions up to and including 2026-01-28 contain a vulnerability in the CSV Log export feature that allows unauthenticated remote attackers to access sensitive information. The vulnerability requires no user interaction and can be exploited over the network by anyone with access to the affected system, making it a straightforward attack with potentially significant exposure of confidential data.
- CVE-2026-39244HIGH 7.5
The adm-zip library before version 0.5.18 contains a memory exhaustion vulnerability triggered by specially crafted ZIP files. When a malicious ZIP file declares an extremely large uncompressed size in its header—while the actual file is tiny—the library allocates huge amounts of memory without checking whether that size is reasonable. A 120-byte malicious ZIP file can trick the library into attempting to allocate 4GB of memory, crashing the application. This happens automatically during any attempt to read or extract the ZIP file, and occurs before the library can validate the file's integrity.
- CVE-2026-39246HIGH 7.5
The decompress library before version 4.2.2 has a vulnerability that allows attackers to create arbitrary symbolic links (symlinks) when extracting archive files. An attacker can craft a malicious archive that, when extracted, creates symlinks pointing to sensitive system files outside the intended extraction directory. This could allow an attacker to trick the application into reading or exposing sensitive information like system passwords. The vulnerability requires no authentication and can be triggered remotely if the application processes untrusted archives.
- CVE-2026-39929HIGH 7.5
Lakeside SysTrack Agent contains a vulnerability that allows an attacker on the network to crash the application by sending a malicious UDP packet. No authentication is required, and the attack does not require user interaction. The vulnerability affects multiple recent versions of the agent and results in denial of service, making it a significant availability risk for organizations relying on SysTrack for endpoint management and monitoring.
- CVE-2026-40006HIGH 7.5
Apache IoTDB has a critical flaw in its optional AirGap pipe receiver feature that allows anyone on the network to crash the system without logging in. When this feature is enabled, the system listens on port 9780 and accepts any connection, then trusts whatever size value an attacker sends, attempting to allocate enormous amounts of memory. A single attacker can exhaust the server's RAM and take down the entire DataNode process. The vulnerability affects IoTDB versions 1.0.0 through 2.0.9, with a fix available in version 2.0.10.
- CVE-2026-40007HIGH 7.5
Apache IoTDB has a remotely exploitable denial-of-service flaw in its AirGap receiver component. When the AirGap receiver feature is enabled, an attacker can send specially crafted network messages that trigger unlimited recursive calls within the receiver's thread, eventually crashing the service by exhausting the Java Virtual Machine's stack memory. No authentication is required to exploit this vulnerability.
- CVE-2026-40140HIGH 7.5
BeyondTrust Remote Support and Privileged Remote Access contain a pre-authentication denial-of-service vulnerability in their network communication layer. An unauthenticated attacker can send specially crafted input to crash or degrade appliance availability without needing valid credentials. The vulnerability stems from insufficient validation of client-supplied data before processing. This affects both products across versions prior to vendor patches.
- CVE-2026-40376HIGH 7.5
Visual Studio Code contains a vulnerability that allows an attacker to gain elevated privileges on a user's system via network-based exploitation. The flaw stems from inadequate validation of user input, which can be triggered when a user interacts with a specially crafted input. While the vulnerability requires user interaction and is somewhat difficult to exploit (high complexity), successful exploitation grants an attacker significant control over the affected system, including the ability to read sensitive data, modify files, and potentially disrupt availability.
- CVE-2026-40452HIGH 7.5
Apache IoTDB contains an authorization flaw in its REST API endpoint `/rest/v2/fastLastQuery` that allows authenticated users to access time-series data they should not be permitted to view. An attacker with valid credentials—but no legitimate access to specific datasets—can retrieve the latest values from sensors, devices, or other IoT sources, potentially exposing sensitive operational or environmental information. This is a classic privilege-escalation scenario where the application fails to enforce proper access controls before returning query results.
- CVE-2026-40454HIGH 7.5
Apache IoTDB's C++ client contains a flaw that causes it to crash when it receives malformed data from a server. An attacker positioned to intercept or manipulate server responses—or operating a malicious IoTDB instance—can send specially crafted messages that trigger an out-of-bounds memory read, crashing the client application. This is a denial-of-service vulnerability affecting IoTDB C++ clients in versions 1.3.5 through 1.3.7 and 2.0.5 through 2.0.9.
- CVE-2026-40519HIGH 7.5
Nginx Proxy Manager contains a flaw that allows authenticated users with certificate management permissions to run arbitrary commands on the server by injecting malicious code into a certificate credential field. When the application restarts, the injected commands execute automatically, giving attackers the ability to take control of the system. Versions 2.9.14 through 2.15.1 are affected; the issue has been patched in a specific code commit.
- CVE-2026-40741HIGH 7.5
A critical access control flaw exists in Redsys for WooCommerce Light versions up to 7.0.0 that allows unauthenticated attackers to modify sensitive data without any form of authentication. The vulnerability does not require a login, special user role, or even interaction from a target user to exploit. An attacker can send a direct request to trigger the flaw and potentially alter order information, payment records, or other transaction data critical to e-commerce operations.
- CVE-2026-40780HIGH 7.5
Liquid Web's BookIt plugin contains a flaw in its password recovery mechanism that allows attackers to bypass authentication. Rather than attacking the login process directly, an attacker can exploit an alternate recovery path to gain unauthorized access without needing valid credentials. This affects BookIt versions before 2.5.4.1.
- CVE-2026-40964HIGH 7.5
A critical authentication flaw in Cloud Foundry's cf-auth-proxy component allows anyone on the internet to forge valid authentication tokens and read all application logs and system metrics without logging in. The vulnerability affects all versions of log-cache_release through v3.2.6, and Cloud Foundry Deployment installations bundling those versions. An attacker needs only network access to the affected component—no special credentials or user interaction required.
- CVE-2026-40983HIGH 7.5
Micrometer, a popular metrics and monitoring library, contains a vulnerability that allows unauthenticated attackers to send specially crafted gRPC requests that overwhelm and crash affected services. An attacker needs only network access to the affected system—no credentials or user interaction required. This is a denial-of-service (DoS) issue affecting specific versions of the library that organizations commonly embed in their Java microservices and cloud-native applications.
- CVE-2026-40984HIGH 7.5
Micrometer, a popular metrics collection library, contains a vulnerability that allows attackers to trigger denial-of-service conditions by sending specially crafted HTTP requests. An unauthenticated attacker on the network can exploit this weakness to make applications unresponsive or crash. The vulnerability affects multiple versions across the micrometer-core and jetty-specific modules. No authentication or user interaction is required to launch an attack.
- CVE-2026-40988HIGH 7.5
Spring Security's SAML 2.0 login and logout functionality has a flaw in how it handles compressed SAML messages sent via the REDIRECT binding. An attacker can send a specially crafted compressed payload that, when decompressed by the application, consumes excessive memory and causes the application to become unavailable. This is a denial-of-service attack that requires no authentication and can be triggered remotely by anyone with network access to the affected application.
- CVE-2026-41006HIGH 7.5
Spring HATEOAS contains a flaw in how it processes certain API response formats (Collection+JSON and UBER). When deserializing these formats, the library uses an internal method that bypasses Jackson's security controls, allowing it to bind properties to Java objects without respecting restrictions that developers have intentionally put in place. This can be exploited to set properties that shouldn't be settable, potentially causing availability issues.
- CVE-2026-41007HIGH 7.5
Spring HATEOAS, a widely used library for building REST APIs with hypermedia support, contains a denial-of-service vulnerability stemming from an unbound cache. Attackers can exploit this by sending specially crafted requests that cause the application to accumulate StringLinkRelation objects indefinitely, eventually exhausting memory and crashing the service. The vulnerability affects multiple versions across the 1.5, 2.3, 2.4, 2.5, and 3.0 release lines.
- CVE-2026-41032HIGH 7.5
CVE-2026-41032 is a high-severity information disclosure vulnerability affecting network controllers. An unauthenticated attacker on the same network segment can download log files from the controller without authentication, potentially exposing sensitive operational data. The vulnerability requires no user interaction and can be exploited over the network, making it a significant confidentiality risk for organizations running vulnerable controller infrastructure.
- CVE-2026-41084HIGH 7.5
A flaw in Apache Airflow's task management API allows an authenticated user with editing permission on one workflow (DAG) to secretly modify task states in completely different workflows—including those owned by other teams. The vulnerability exploits a mismatch between authorization checks (which validate against the workflow in the URL) and the actual workflow being modified (specified in the request body). An attacker with legitimate access to edit one workflow can bypass permission controls to interfere with unrelated workflows, potentially disrupting operations, hiding failures, or triggering unintended task executions.
- CVE-2026-41523HIGH 7.5
vLLM, a popular open-source inference engine for large language models, contains a critical vulnerability in versions before 0.22.0 that allows attackers to execute arbitrary code on affected servers. The vulnerability exploits a flawed security check in the activation function loader and can be triggered when vLLM runs in Python optimized mode (using the -O flag or PYTHONOPTIMIZE environment variable). An attacker can exploit this by publishing a malicious model to HuggingFace that, when loaded by vLLM, executes arbitrary code on the host. No authentication is required, and the attack requires only that a user interact with the malicious model.
- CVE-2026-41565HIGH 7.5
CryptX, a cryptographic library for Perl, contains a stack buffer overflow vulnerability in its AEAD (Authenticated Encryption with Associated Data) decryption functions. When these functions process an authentication tag longer than expected, they overflow a fixed-size buffer on the stack, potentially corrupting memory and crashing the application. An attacker who can supply a maliciously long authentication tag to vulnerable code paths can trigger this crash. The vulnerability affects four specific decryption functions: gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify, and eax_decrypt_verify. Patches were released incrementally, with gcm_decrypt_verify fixed in version 0.088 and the remaining three functions addressed in version 0.088_001.
- CVE-2026-41577HIGH 7.5
Authentik, an open-source identity provider, contains a flaw in how it processes SAML authentication assertions. The software fails to validate time-based and audience restrictions on these assertions, meaning an attacker could replay old, expired authentication tokens or use tokens intended for a different service. This could allow unauthorized access to systems relying on authentik for authentication.
- CVE-2026-41695HIGH 7.5
Spring Data Commons, a widely-used Java framework component, contains a denial-of-service vulnerability in how it processes property path strings. An attacker can send specially crafted requests that cause the application to exhaust system resources (CPU, memory) during property resolution, making the service unavailable to legitimate users. This affects versions 3.4.0 through 3.4.14, 3.5.0 through 3.5.11, and 4.0.0 through 4.0.5.
- CVE-2026-41708HIGH 7.5
Spring Cloud Sleuth versions 3.1.0 through 3.1.13 contain a denial-of-service vulnerability that allows unauthenticated network-based attackers to crash or severely degrade applications. The flaw resides in the transaction instrumentation layer and can be triggered by specially crafted API calls. Organizations using affected versions with Spring TX instrumentation enabled are at risk.
- CVE-2026-41716HIGH 7.5
Spring Data Commons contains a vulnerability in how it caches internal property lookups. An attacker can exploit this by sending specially crafted requests that cause the cache to store attacker-controlled strings as permanent cache keys. Because these keys are never cleaned up, repeated requests will gradually consume all available heap memory, eventually crashing the application. This is a denial-of-service attack that requires no authentication and can be triggered from the network.
- CVE-2026-41728HIGH 7.5
Spring Data REST, a widely-used framework for building REST APIs on top of Spring Data repositories, contains an authorization bypass vulnerability in its JSON Patch implementation. When processing JSON Patch requests (which use the application/json-patch+json content type), the framework fails to properly enforce write-access restrictions on intermediate steps of multi-level object paths. This means an attacker can craft a malicious patch request that modifies protected fields by traversing through intermediate objects without the framework validating permissions at each step. The vulnerability affects a broad range of versions across multiple release lines, potentially impacting many Spring-based microservices and REST APIs.
- CVE-2026-41842HIGH 7.5
Spring Framework versions 5.3 through 7.0 contain a denial-of-service vulnerability in their static resource resolution code. An unauthenticated attacker can craft requests that cause Spring MVC and WebFlux applications to consume excessive resources, potentially rendering the application unavailable. No user interaction is required, and the attack works over the network. The vulnerability affects a wide range of Spring versions released over several years, making it relevant to many production deployments.
- CVE-2026-41849HIGH 7.5
Spring Framework versions 5.3.0 through 5.3.48 contain an integer overflow flaw in the Spring Expression Language (SpEL) evaluation engine. By crafting a malicious SpEL expression, an unauthenticated attacker can trigger uncontrolled resource consumption on the affected system, leading to denial of service. No authentication is required, and the attack can be mounted remotely over the network.
- CVE-2026-41850HIGH 7.5
Spring Framework contains a vulnerability in how it evaluates user-supplied SpEL (Spring Expression Language) expressions. An attacker can craft a malicious expression that forces the application to consume excessive CPU or memory during processing, causing the application to slow down or become completely unavailable. This only affects applications that directly evaluate untrusted SpEL input—not all Spring applications are vulnerable. The vulnerability impacts multiple recent versions of Spring Framework across the 5.3, 6.1, 6.2, and 7.0 release lines.
- CVE-2026-41856HIGH 7.5
Spring for GraphQL has a flaw in how it detects security annotations on data fetcher methods. When methods are inherited or defined in type hierarchies, the framework may fail to recognize authorization annotations at runtime, allowing requests that should be blocked by security rules to proceed. This affects multiple versions across the 1.x and 2.x release lines.
- CVE-2026-41858HIGH 7.5
BOSH-Ecosystem's windows-utilities-release contains a critical password generation flaw that undermines a key security hardening measure. The tool is designed to lock down Windows VMs by setting an Administrator account password that should be cryptographically random and unguessable. However, the password generation relies on a predictable random number generator seeded only with the system clock. An attacker who can estimate when a VM was booted can narrow down the possible passwords to a small, brute-forceable set, potentially recovering the Administrator credential and gaining full control of the system.
- CVE-2026-41896HIGH 7.5
Coolify, an open-source platform for managing servers and applications, contains a critical authentication bypass in its webhook validation system. When a Coolify application is first created, the webhook secret used to verify GitHub webhook requests is left null (empty). Due to how PHP handles null values in cryptographic functions, this null secret gets treated as an empty string, allowing attackers to calculate the expected signature themselves. By forging a valid webhook signature, an attacker can trigger unauthorized deployments without any authentication. This affects all Coolify versions before 4.0.0-beta.474.
- CVE-2026-41992HIGH 7.5
GNU gzip contains a buffer overflow vulnerability in how it handles compressed files using the LZH format. The flaw arises because gzip reuses the same memory structures across different compression formats (LZ77, LZW, and LZH) without resetting them between files. An attacker can craft two specially designed compressed files—a LZW file followed by an LZH file—and have both decompressed in a single command. The first file poisons the shared memory with invalid data, causing the second file's decompression to read beyond allocated memory boundaries. This can leak sensitive information from the server or process memory.
- CVE-2026-42127HIGH 7.5
A vulnerability in Grafana's public dashboard query endpoint allows attackers to crash the service by sending extremely large requests without needing any credentials. The vulnerability stems from missing request size validation, which permits an attacker to force the server to allocate unbounded memory until it runs out of resources. This is a straightforward denial-of-service attack that requires only network access to an exposed Grafana instance.
- CVE-2026-42342HIGH 7.5
React Router and Remix applications using Framework Mode are vulnerable to a denial-of-service attack via crafted requests that exploit unbounded path expansion in the __manifest endpoint. An unauthenticated attacker can send specially constructed requests that cause the server to consume excessive resources, slowing response times or rendering the application unavailable to legitimate users. This does not affect applications built with Declarative Mode or Data Mode routing patterns.
- CVE-2026-42504HIGH 7.5
A vulnerability exists in MIME header parsing where specially crafted email headers containing multiple invalid encoded-words can trigger excessive CPU consumption, effectively causing a denial of service. An attacker can send a malicious email with a crafted header to impact system availability without requiring authentication or user interaction.
- CVE-2026-42536HIGH 7.5
A heap-based buffer overflow vulnerability exists in Apache HTTP Server versions 2.4.0 through 2.4.67 when processing XML content through the mod_xml2enc module. An attacker can send specially crafted XML data to trigger a memory corruption issue that causes the server to crash, resulting in denial of service. The vulnerability requires no authentication and can be exploited over the network without user interaction.
- CVE-2026-42542HIGH 7.5
TDengine versions 3.4.0.0 through 3.4.1.5 contain a flaw that allows an attacker on the network to crash the taosd server process by sending a single specially crafted RPC packet. No authentication, login credentials, or prior interaction with the system is required—an attacker can trigger the crash from scratch. The vulnerability has been patched in version 3.4.1.6.
- CVE-2026-42567HIGH 7.5
Svelte, a popular web framework known for performance, contains a vulnerability in its runtime that can be exploited to cause denial-of-service attacks. When certain dynamic element tags are processed, an internal regular expression pattern can consume exponential amounts of computation time, effectively freezing or crashing an application. Attackers can trigger this by sending crafted input to applications using affected Svelte versions, disrupting service availability without needing authentication or special privileges.
- CVE-2026-42570HIGH 7.5
Svelte devalue is a widely-used JavaScript library for serializing complex data structures. Versions 5.6.3 through 5.8.0 contain a flaw in the deserialization function (devalue.parse) that allows an attacker to trigger excessive memory allocation by sending specially crafted sparse array payloads. Depending on JavaScript engine implementation quirks, this can exhaust available memory and crash applications that depend on devalue. The issue does not affect confidentiality or integrity—only availability. It has been resolved in version 5.8.1.
- CVE-2026-42668HIGH 7.5
The Email Marketing for WooCommerce plugin by Omnisend contains a critical authentication bypass vulnerability affecting versions 1.18.0 and earlier. An unauthenticated attacker can access sensitive email marketing functionality without valid credentials, potentially exposing customer data and campaign information. This vulnerability requires no user interaction and can be exploited remotely by any threat actor with network access to an affected WooCommerce store.
- CVE-2026-42669HIGH 7.5
EventPrime versions through 4.3.2.0 contain a missing authorization vulnerability that allows unauthenticated attackers to modify data or perform actions they should not have access to. The flaw stems from improperly configured access control checks, meaning the application fails to verify user permissions before allowing sensitive operations. An attacker on the network can exploit this without credentials or user interaction, potentially altering event configurations, participant data, or other critical information depending on EventPrime's scope.
- CVE-2026-42670HIGH 7.5
CVE-2026-42670 is a missing authorization flaw in Etoile Web Design Incorporated's Five Star Restaurant Reservations system. An attacker can access sensitive data by exploiting improperly configured access controls without needing credentials or user interaction. The vulnerability allows unauthenticated remote access to confidential information, presenting a direct risk to restaurant operations and customer data.
- CVE-2026-42673HIGH 7.5
Logtivity's Activity Logs plugin leaks sensitive information that should not be transmitted. The vulnerability allows unauthorized users to retrieve embedded sensitive data through the plugin's normal network communication channels. This affects all versions through 3.3.6 and requires patching to prevent data exposure.
- CVE-2026-42674HIGH 7.5
The Advanced Access Manager (AAM) plugin contains a vulnerability that allows attackers to bypass authentication by spoofing requests through URL encoding techniques. An attacker can craft specially encoded URLs to circumvent access controls without needing valid credentials, potentially gaining unauthorized access to protected resources. This affects AAM versions up through 7.1.0.
- CVE-2026-42677HIGH 7.5
A missing authorization flaw in WP Document Revisions allows unauthenticated attackers to access sensitive documents by exploiting improperly configured security levels. The vulnerability affects how the plugin enforces access control rules, enabling unauthorized users to view confidential information stored within the WordPress environment.
- CVE-2026-42764HIGH 7.5
OpenSSL's QUIC server implementation contains a flaw that can crash the server when it receives specially crafted initial connection packets. This only affects servers that have explicitly disabled address validation—a non-default setting. An unauthenticated attacker on the network can exploit this by sending a QUIC initial packet with an invalid token, causing the server process to terminate abruptly and become unavailable. The vulnerability does not lead to data theft or unauthorized access, only service disruption.
- CVE-2026-42765HIGH 7.5
CVE-2026-42765 is a denial-of-service vulnerability in OpenSSL that crashes applications when two specific certificate verification features are enabled simultaneously. The flaw occurs when OCSP response checking for the entire certificate chain is combined with partial-chain verification, and the chain lacks a self-signed trusted root certificate. Under these conditions, the code attempts to dereference a NULL pointer, causing the application to crash. Since both features are disabled by default in OpenSSL, real-world risk is limited to applications that explicitly enable both flags.
- CVE-2026-42908HIGH 7.5
A flaw in Windows Remote Desktop Protocol (RDP) allows an attacker on the network to read memory from the RDP service without authentication, potentially exposing sensitive information. The vulnerability requires no user interaction and can be exploited remotely by anyone with network access to an affected system running RDP. This is a confidentiality risk—the attacker cannot modify data or disrupt service, but unauthorized disclosure of system or user data is possible.
- CVE-2026-42909HIGH 7.5
A race condition flaw in Microsoft's Remote Desktop Client and related Windows components allows an attacker to execute malicious code on a target machine over the network. The vulnerability requires the user to interact with a malicious connection or file, but once triggered, grants the attacker the same privileges as the logged-in user. This affects multiple versions of Windows 10, Windows 11, Windows Server, and the standalone Windows App, making it a broad-reaching concern across enterprise environments.
- CVE-2026-42913HIGH 7.5
A race condition flaw in Remote Desktop Client allows an attacker to execute arbitrary code on a Windows system by exploiting a window between when two processes access shared resources without proper locking. The attack requires network access and user interaction (such as establishing an RDP session), but successfully exploiting it grants full code execution with the privileges of the Remote Desktop Client process. This affects multiple Windows 11 versions and Windows Server 2022/2025.
- CVE-2026-42992HIGH 7.5
A heap-based buffer overflow vulnerability exists in Microsoft Remote Desktop Client that could allow an attacker to execute malicious code on a user's machine over the network. The attack requires user interaction (such as connecting to a malicious RDP server) and involves complex conditions to exploit, but if successful would grant an attacker full control over the affected system. This is a serious flaw affecting multiple Windows versions and server platforms.
- CVE-2026-42993HIGH 7.5
A heap-based buffer overflow vulnerability exists in Microsoft's Remote Desktop Client that allows attackers to execute arbitrary code on affected systems over the network. The vulnerability requires user interaction (such as clicking a malicious file or accepting a connection) and success depends on system configuration, but once exploited grants full code execution with the privileges of the logged-in user. This affects multiple versions of Windows 10, Windows 11, and Windows Server 2022–2025.
- CVE-2026-44017HIGH 7.5
Docling, a document processing library, contains a vulnerability in how it downloads and extracts AI model files. Before version 2.91.0, the software did not properly validate file paths when extracting ZIP archives, allowing an attacker who intercepts or compromises the model download source to write files anywhere on the system where the application has write access. This could lead to remote code execution, persistent backdoors, or data destruction. The vulnerability requires attackers to first compromise the download source—either through supply chain attacks, DNS spoofing, or man-in-the-middle interception—making it a moderately difficult but high-impact attack.
- CVE-2026-44020HIGH 7.5
Docling, a document processing library that handles multiple file formats and integrates with AI systems, contains a critical XML parsing vulnerability in its USPTO patent document handlers. Versions 2.13.0 through 2.74.0 parse untrusted XML without protection against external entity injection. An attacker who can supply a malicious USPTO patent XML file to an affected Docling deployment can read sensitive files from the server, pivot to internal systems via SSRF, or exhaust resources to crash the service. The vulnerability was resolved in version 2.74.0.
- CVE-2026-44025HIGH 7.5
Fluentd's Monitor Agent plugin exposes sensitive internal data through publicly accessible REST API endpoints. Before version 1.19.3, responses from endpoints like /api/plugins.json leak internal system variables that may contain database passwords, API keys, and cloud credentials. An attacker with network access to the monitoring API can retrieve these secrets without authentication, potentially compromising connected databases and cloud services.
- CVE-2026-44160HIGH 7.5
Fluentd versions before 1.19.3 contain a denial-of-service vulnerability in the in_http and in_forward plugins. The plugins accept gzip-compressed data but only limit the size of the *compressed* payload, not the decompressed output. An attacker can send a specially crafted compressed message that expands to an enormous size when decompressed, exhausting the server's memory and causing Fluentd to become unavailable. This affects any Fluentd deployment that receives data from untrusted networks or users.
- CVE-2026-44250HIGH 7.5
Netty's Redis codec library has a denial-of-service vulnerability where attackers can craft specially formed Redis messages with deeply nested array structures. When processed, these payloads force the affected server to create and hold vast numbers of internal state objects, consuming memory until the application crashes with an OutOfMemoryError. This impacts applications using Netty's Redis protocol handling before specific patch versions.
- CVE-2026-44422HIGH 7.5
FreeRDP, a widely-used open-source Remote Desktop Protocol client, contains a memory corruption vulnerability in its authentication-redirection subsystem. A malicious RDP server can craft specially-formed authentication data that causes the FreeRDP client to allocate a single heap object but then attempt to free it twice—or use it after the first deallocation. This occurs because the parser doesn't properly track which heap objects correspond to which data structures when the same object reference is reused. The result is a crash or potential code execution on the client machine. The vulnerability requires user interaction (connecting to a malicious server) but affects all FreeRDP versions before 3.26.0.
- CVE-2026-44486HIGH 7.5
Axios, a widely-used HTTP client library for JavaScript, has a credential leakage vulnerability in its Node.js implementation. When your application uses Axios to make requests through an authenticated proxy, the library can accidentally include proxy login credentials in subsequent requests if it follows a redirect to a different server. This happens because Axios retains the Proxy-Authorization header even when the redirected request no longer routes through the original proxy. Browser-based Axios applications are unaffected; only Node.js deployments with automatic redirect handling and proxy authentication are vulnerable.
- CVE-2026-44487HIGH 7.5
Axios, a widely-used HTTP client library for Node.js and browsers, has a credential leakage vulnerability in its redirect-handling logic. When an application makes an HTTP request through an authenticated proxy and then follows a redirect to a destination that no longer requires the proxy, Axios may mistakenly send the proxy's authentication credentials to the final destination. An attacker controlling or observing that final destination could capture credentials intended only for the proxy, potentially gaining unauthorized access to internal proxy infrastructure. This flaw affects Axios versions before 0.32.0 and 1.16.0.
- CVE-2026-44488HIGH 7.5
Axios, a widely-used HTTP client library for JavaScript applications, contains a vulnerability in versions 1.7.0 through 1.15.x that bypasses size limits when using the fetch adapter. When developers configure maxContentLength or maxBodyLength to restrict how much data can be sent or received, those limits are ignored if the fetch adapter is active. An attacker or compromised server can exploit this to send oversized responses that exhaust application resources, or an application forwarding untrusted request bodies may inadvertently process larger payloads than intended. The vulnerability is resolved in Axios 0.32.0 and 1.16.0.
- CVE-2026-44496HIGH 7.5
Axios, a widely-used HTTP client library for JavaScript applications, contains a vulnerability in how it processes XSRF (cross-site request forgery) cookie names. When building a security check, the library doesn't properly escape special characters used in regular expressions, allowing an attacker to craft a malicious cookie name that triggers expensive computational operations. In browser environments, this causes the application to freeze or become unresponsive while processing requests. The vulnerability does not affect Node.js server applications, React Native, or web workers. Versions 0.32.0 and later on the 0.x line and 1.16.0 and later on the 1.x line resolve this issue.
- CVE-2026-44594HIGH 7.5
esm.sh, a popular CDN for JavaScript development that eliminates the need for build processes, contains a vulnerability in how it processes package metadata. An attacker can publish a malicious npm package that tricks the esm.sh server into reading and exposing sensitive files from its own filesystem. This happens because the service doesn't properly validate how it interprets the 'browser' field in package.json during the build process. While the attacker cannot modify files or crash the service, they can gain unauthorized access to confidential data stored on esm.sh infrastructure.
- CVE-2026-44628HIGH 7.5
CVE-2026-44628 is a denial-of-service vulnerability affecting worklist servers that allows an unauthenticated attacker to crash the service by sending a specially crafted query. The attack succeeds only when specific conditions are met: the server must have a valid Called AE Title (an identifier used in DICOM medical imaging protocols), a corresponding storage directory, an expected lockfile, and at least one matching worklist record in the database. Once triggered, the crash renders the worklist service unavailable until manual restart.
- CVE-2026-44648HIGH 7.5
SillyTavern, a locally installed interface for interacting with large language models and related AI services, contains a session management vulnerability in versions prior to 1.18.0. When users change their password or complete account recovery, the application updates the password hash in its database but fails to invalidate existing user sessions. Because SillyTavern uses stateless, client-side cookie storage for authentication data, the server has no mechanism to revoke tokens after they're issued. An attacker who gains access to a user's session cookie—either through theft, interception, or social engineering—can continue using that session even after the legitimate user changes their password, maintaining unauthorized access to the account and its associated permissions.
- CVE-2026-44716HIGH 7.5
Pipecat, an open-source Python framework for building voice and conversational AI agents, contains a path traversal vulnerability in its development runner. When started with the --folder flag, the runner exposes an unauthenticated file download endpoint that fails to validate user-supplied filenames. An attacker on the network can craft specially-encoded URLs to read files anywhere on the system that the Pipecat process can access—such as SSH keys, API credentials, configuration files, and system files. The vulnerability affects versions 0.0.90 through 1.1.x and has been fixed in version 1.2.0.
- CVE-2026-44786HIGH 7.5
Discourse, a popular open-source discussion platform, has a flaw in how it handles chat messages for public categories. When users post in public category chat channels, the system broadcasts those messages through MessageBus—a real-time messaging system—without properly checking who should be allowed to see them. This means anyone subscribed to MessageBus, even if they don't have chat functionality enabled, could receive and read private chat message content they shouldn't have access to. The issue affects Discourse versions released from early 2026 through mid-2026, but patches are now available.
- CVE-2026-44799HIGH 7.5
A heap-based buffer overflow vulnerability exists in Microsoft's Remote Desktop Client and related Windows components. An attacker can exploit this flaw remotely by sending specially crafted network traffic, potentially allowing them to execute arbitrary code with the privileges of the user running the vulnerable application. User interaction is required to trigger the vulnerability, such as opening a malicious remote desktop connection or accepting a prompt. This affects a wide range of Windows versions and Server editions.
- CVE-2026-44801HIGH 7.5
A use-after-free vulnerability in Microsoft's Remote Desktop Client and Windows versions allows an attacker to execute code on your computer over the network. The flaw requires user interaction (such as clicking a link or opening a file) and specific system conditions, but once triggered, grants full control of the affected machine. This affects Remote Desktop Client, Windows App, and multiple Windows 10, 11, and Server editions.
- CVE-2026-44840HIGH 7.5
Dgraph versions before 25.3.4 contain a query injection vulnerability in the `checkUserPassword` GraphQL endpoint. Attackers can exploit this by submitting specially crafted passwords that break out of the intended query structure and inject arbitrary database commands. The vulnerability requires no authentication and can be triggered remotely, allowing attackers to read sensitive data from the database without permission.
- CVE-2026-44883HIGH 7.5
Portainer Community Edition versions between 2.33.0 and 2.33.7, 2.39.1, and 2.40.x contain a flaw in how they handle authentication tokens. The platform accepts JWT authentication tokens passed as URL query parameters (e.g., ?token=<JWT>) alongside the standard Authorization header. Because URLs are logged in reverse-proxy access logs, browser history, and Referer headers, tokens transmitted this way can be intercepted by anyone with access to those logs or by downstream websites users visit. Any leaked token provides complete access to the user's account for up to 8 hours (or longer if expiration is customized). This particularly affects users with container exec or attach permissions, not just administrators.
- CVE-2026-44890HIGH 7.5
Netty's Redis codec (the component that reads and interprets Redis protocol messages) has a memory exhaustion vulnerability. An attacker can send malformed Redis messages across many connections to deliberately exhaust the server's direct memory buffer pool, causing an OutOfDirectMemoryError. This denies service to legitimate users. The flaw exists in Netty versions before 4.1.135.Final and 4.2.15.Final, which include fixes.
- CVE-2026-44892HIGH 7.5
Netty, a widely-used Java framework for building network applications, has a flaw in its HTTP/3 implementation that fails to enforce limits on the size of request headers. An attacker can exploit this by sending an extremely large number of headers, causing the affected application to consume excessive memory and crash. This denial-of-service vulnerability affects versions prior to 4.2.15.Final and has a CVSS score of 7.5 (HIGH). The fix is available in version 4.2.15.Final and later.
- CVE-2026-44893HIGH 7.5
Netty's HAProxy protocol decoder has a resource leak vulnerability triggered by malformed protocol messages. When an attacker sends a specially crafted HAProxy TLV (Type-Length-Value) structure with an undersized length field, the decoder attempts to read data beyond the declared bounds. The exception that follows bypasses the error handler, leaving memory buffers permanently unreleased. This cumulates over repeated malicious messages, exhausting available memory and crashing the application.
- CVE-2026-44894HIGH 7.5
Netty versions prior to 4.2.15.Final contain a flaw in their default token validation logic for QUIC connections. When an application uses Netty's NoQuicTokenHandler (the built-in fallback when no custom handler is configured), the server incorrectly treats unauthenticated tokens as valid. An attacker can exploit this by sending a specially crafted QUIC Initial packet with a spoofed victim IP address and arbitrary token bytes. The server will then bypass its normal traffic rate-limiting safeguards and send full-size handshake responses (including certificates) toward the spoofed IP without restriction. This enables a reflection-based amplification attack where the attacker uses your Netty server to overwhelm a victim with QUIC handshake traffic.
- CVE-2026-45017HIGH 7.5
Python Liquid is a templating engine used to process dynamic content. Versions before 2.2.0 contain a path traversal flaw that lets an attacker with the ability to author templates bypass security restrictions and read arbitrary files from the server. An attacker could use the {% include %} or {% render %} template tags with absolute file paths to access files outside the intended template directory. The compromised files are then processed as templates, potentially exposing their contents. This requires the attacker to have template authoring privileges and targets files readable by the application.
- CVE-2026-45290HIGH 7.5
Cloudburst Network is a library used by many projects to handle networking tasks. A flaw in versions before 1.0.0.CR3-20260417.085727-30 allows attackers on the network to crash the core event loop that handles network communications, making affected applications unresponsive. Any software using the vulnerable Cloudburst Network library should upgrade immediately; there is no safe workaround.
- CVE-2026-45291HIGH 7.5
Cloudburst Network is a library used by many networked applications to handle low-level communication. A flaw in versions before 1.0.0.CR3-20260418.124334-32 allows anyone on the internet to send specially crafted requests that crash the network connection, causing the affected application to stop communicating. The vulnerability requires no authentication or user interaction—an attacker simply needs network access to trigger it. While the impact is limited to availability (the connection goes down), the ease of exploitation and broad accessibility make this a significant concern for any publicly facing service using vulnerable Cloudburst Network versions.
- CVE-2026-45332HIGH 7.5
Automad versions 2.0.0-alpha.1 through 2.0.0-beta.27 contain a critical configuration flaw that exposes administrator password hashes to anyone on the internet. The setup endpoint designed to create the first user account remains publicly accessible after installation completes, leaking sensitive credential data without authentication. An attacker can retrieve every administrator's bcrypt hash with a single request, enabling offline password cracking attacks.
- CVE-2026-45357HIGH 7.5
LiquidJS, a JavaScript template engine compatible with Shopify and GitHub Pages, has a denial-of-service vulnerability in versions 10.25.7 and earlier. The date filter's strftime implementation fails to validate width specifiers (e.g., %5000000d), allowing attackers to craft small templates that generate enormous amounts of output and consume excessive memory and CPU. The vulnerability bypasses built-in resource limits that documentation claims should prevent this type of attack. A single malicious template can trigger out-of-memory crashes or make applications unresponsive.
- CVE-2026-45416HIGH 7.5
Netty, a widely-used Java framework for building network applications, contains a memory exhaustion vulnerability in its TLS handshake handler. When processing incoming TLS ClientHello messages, the framework can be tricked into allocating extremely large buffers—up to 16 megabytes or more—without proper validation. An attacker sending specially crafted TLS requests can exhaust server memory and cause denial of service. The issue affects Netty versions before 4.1.135.Final and 4.2.15.Final and is most dangerous when the framework is used with common SNI (Server Name Indication) handler configurations that disable safeguards by default.
- CVE-2026-45445HIGH 7.5
OpenSSL has a flaw in its AES-OCB encryption handling when applications use the lower-level one-shot EVP_Cipher() interface. The supplied encryption key (IV) is ignored, causing every message encrypted under the same key to use an identical effective nonce. This breaks the confidentiality guarantee of the encryption and, worse, enables attackers to forge authentication tags—meaning they can create fake encrypted messages that will be accepted as legitimate. The issue only affects applications that directly use the EVP_Cipher() one-shot API with AES-OCB; applications using the recommended streaming interface or TLS connections are not at risk.
- CVE-2026-45541HIGH 7.5
A flaw exists in Espressif's IoT Development Framework (ESP-IDF) that allows an attacker to crash a WebSocket server by sending a specially crafted network request during the initial connection handshake. The server fails to safely validate a specific HTTP header before attempting to process it, causing an immediate denial of service. No authentication is required—an unauthenticated attacker on the network can trigger this crash remotely.
- CVE-2026-45553HIGH 7.5
NiceGUI, a Python UI framework, has a file disclosure vulnerability in its reStructuredText rendering feature. When applications pass user-controlled input to the ui.restructured_text() function, attackers can exploit standard reStructuredText directives to read arbitrary files from the server. This only affects applications that process untrusted content; those using only static, trusted strings are safe. The issue is fixed in version 3.12.0.
- CVE-2026-45583HIGH 7.5
Microsoft Exchange Server contains a code injection vulnerability that allows an attacker to execute arbitrary code on affected systems over the network. The vulnerability requires user interaction and moderately complex attack conditions, but successful exploitation could give an attacker complete control over the Exchange server and the email infrastructure it supports. This is a HIGH severity issue affecting multiple versions of Exchange Server and Exchange Server Subscription Edition.
- CVE-2026-45591HIGH 7.5
CVE-2026-45591 is a denial-of-service vulnerability in ASP.NET Core that allows attackers on a network to exhaust system resources and crash or degrade application availability. An attacker can send specially crafted requests that consume excessive CPU, memory, or other finite resources without needing to authenticate or interact with users. The vulnerability stems from insufficient input validation or rate-limiting in the framework's request-handling pipeline.
- CVE-2026-45617HIGH 7.5
LiquidJS, a popular template engine used by Shopify and GitHub Pages, contains a denial-of-service flaw in its strip_html filter that can freeze Node.js applications. Attackers can craft malicious input—such as 350 KB of repeated `<script` tags—that causes the filter's underlying regex to perform excessive backtracking, consuming CPU and blocking the event loop for seconds. This happens without any authentication required, making it trivial to exploit via a single HTTP request containing untrusted template data. The vulnerability affects all versions up to 10.25.7 and is resolved in 10.26.0.
- CVE-2026-45639HIGH 7.5
A flaw in Windows Remote Desktop Protocol (RDP) allows attackers to read sensitive data from memory without authentication or user interaction. An attacker on the network could exploit this vulnerability to extract confidential information, though they cannot modify systems or cause outages. The vulnerability affects numerous Windows versions and related RDP clients.
- CVE-2026-45678HIGH 7.5
OpenTelemetry eBPF Instrumentation versions before 0.9.0 contain a denial-of-service vulnerability in their Postgres protocol parser. When the parser processes a specially crafted BIND message with an empty or unterminated portal name, it attempts to read beyond the buffer boundary, causing the instrumentation service to crash. An unauthenticated network attacker can trigger this crash, disrupting observability and monitoring capabilities for applications relying on this instrumentation.
- CVE-2026-45685HIGH 7.5
OpenTelemetry eBPF Instrumentation versions 0.1.0 through 0.8.x contain a denial-of-service vulnerability in their MongoDB wire protocol parser. An attacker on the network can send specially crafted MongoDB messages to crash the telemetry agent without needing authentication or user interaction. When the malformed message reaches the parser, it triggers an unhandled panic that terminates telemetry collection for the affected process or entire node. This is a remote, unauthenticated attack that requires only network access to the listening port.
- CVE-2026-45686HIGH 7.5
OpenTelemetry eBPF Instrumentation versions 0.7.0 through 0.8.x contain a flaw in their memcached protocol parser that allows a remote attacker to crash the instrumentation process. By sending a specially crafted memcached command with an extremely large byte count, an attacker can trigger an integer overflow that wraps the calculated payload length into a negative number, causing the process to panic and stop functioning. This results in a denial-of-service condition affecting any system relying on this instrumentation for observability.
- CVE-2026-45771HIGH 7.5
FreeSWITCH versions before 1.11.0 contain a denial-of-service vulnerability in their XML parser that allows an unauthenticated attacker to crash or severely degrade the system by sending a specially crafted SIP message. The attack exploits a classic "billion laughs" XML expansion flaw, where nested entity definitions cause exponential memory and CPU consumption. Because the malicious payload is processed before authentication checks, an attacker on the network can trigger the vulnerability without credentials—a single request is enough to cause significant resource exhaustion.
- CVE-2026-45783HIGH 7.5
A vulnerability in libp2p (a JavaScript networking library) before version 16.2.6 allows any unauthenticated attacker on the network to crash kad-dht nodes running in server mode by flooding them with specially crafted messages. The attacker doesn't need valid credentials or an established connection—they can simply send a stream of PUT_VALUE messages with keys designed to bypass content validation. These messages accumulate on the target node's disk until storage is exhausted, rendering the node unavailable. The attack is trivial to execute and requires no special network position or protocol manipulation beyond crafting the malicious keys.