2026 CVE Vulnerabilities
64,732 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84893 | HIGH | 7.6 | — | Sep 25, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could ex... |
| CVE-2026-84884 | HIGH | 7.5 | — | Sep 25, 2026 | IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent fo... |
| CVE-2026-100176 | HIGH | 8.5 | — | Sep 25, 2026 | The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported fro... |
| CVE-2026-100172 | HIGH | 8.5 | — | Sep 25, 2026 | The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 t... |
| CVE-2026-88421 | HIGH | 7.5 | — | Sep 25, 2026 | Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthentica... |
| CVE-2026-79153 | HIGH | 7.8 | — | Sep 25, 2026 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driv... |
| CVE-2026-52622 | HIGH | 7.5 | — | Sep 25, 2026 | An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 befo... |
| CVE-2026-51773 | HIGH | 8.1 | — | Sep 25, 2026 | An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously... |
| CVE-2026-98156 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/virtio: use the DMA API for resource backing on... |
| CVE-2026-98154 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix -EIO cleanup order in queue_rq On -... |
| CVE-2026-98150 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix BPF_F_CPU validation for sparse CPU IDs B... |
| CVE-2026-98143 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Don't read the U65 rounding mode as ... |
| CVE-2026-98130 | HIGH | 8.1 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START Th... |
| CVE-2026-98122 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_... |
| CVE-2026-98116 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Serialize PCM mmap with buffer reallocat... |
| CVE-2026-98115 | HIGH | 8.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions during logoff SMB3 mu... |
| CVE-2026-98112 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix listener task lifetime on netdev events ... |
| CVE-2026-98108 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + E... |
| CVE-2026-98096 | HIGH | 7.4 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: restore network header before routing and... |
| CVE-2026-98083 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction use-after-free in raid strip... |
| CVE-2026-98073 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: Remove conflicting altnames for dying netns in... |
| CVE-2026-98070 | HIGH | 8.1 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callb... |
| CVE-2026-98069 | HIGH | 8.1 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire the fastpath locks in rds_conn_shu... |
| CVE-2026-98056 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme: remove stale namespaces by NSID range during ... |
| CVE-2026-98052 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: clear txcb->last before writing each d... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now