Back to blog
CVE2026vulnerabilities

Critical vulnerabilities 2026: CVEs affecting your stack

Published on 2026-04-097 min readFlorian

The 2026 threat landscape

35 CVEs attributed to AI code in March 2026. Applications built with Cursor, Lovable and Bolt are particularly affected.

WordPress

Plugins remain the weak link. ACF, WPForms, Elementor vulnerabilities exposed millions of sites.

Laravel

Ziggy route exposure, Debugbar in production, API endpoints without auth middleware.

Supabase

RLS errors remain vulnerability #1. Tables without policies, USING(true), unprotected RPC functions.

Node.js & n8n

n8n had 6 critical CVEs in 3 months early 2026.

Related articles

Three adjacent analyses to keep exploring the same attack surface.

Sources

Written by Florian
Reviewed on 2026-04-09

Editorial analysis based on official vendor, project, and regulator documentation.

Related services

If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

Need an external review of your HR SaaS?

Share your product, stack, and client context. We will come back with the right review scope.

Discuss your audit