2026 CVE Vulnerabilities
64,734 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-98050 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_ptp: Fix napi_gro_receive() call fr... |
| CVE-2026-98041 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Don't predict JMP32 pointer vs zero comparison... |
| CVE-2026-98030 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: dsa: bcm_sf2: bound the CFP rule dump by the c... |
| CVE-2026-98029 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: eth: nfp: bound the ntuple rule dump by the caller'... |
| CVE-2026-98027 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: bound the policy rule dump by ... |
| CVE-2026-98023 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vxlan: reject dynamic fdb entries that reference a ... |
| CVE-2026-98017 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: defer qdisc freeing after failed creatio... |
| CVE-2026-98002 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix ineffective error check in nested do... |
| CVE-2026-97991 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_blk: reject out-of-range sector starts vd... |
| CVE-2026-97990 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_net: check TX pull result before RX copy ... |
| CVE-2026-97971 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nstree: check listing permission before taking a na... |
| CVE-2026-97957 | HIGH | 8.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: hinic: fix mailbox segment buffer overflow ch... |
| CVE-2026-97953 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TX descriptor availability check f... |
| CVE-2026-97941 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/slab: take n->list_lock in __slab_try_return_fre... |
| CVE-2026-97940 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix fib6 walker UAF on seq stop ipv6_route_i... |
| CVE-2026-97937 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ftrace: fork: Initialize function graph state befor... |
| CVE-2026-97931 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: us122l: Prevent write upgrades for read mappi... |
| CVE-2026-97926 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ufs: validate cylinder group metadata before cachin... |
| CVE-2026-97911 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure SRAM region size matches job ... |
| CVE-2026-97910 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: sprd: validate compress buffer sizes against ... |
| CVE-2026-97903 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: exit: hold a reference to thread_pid across proc_fl... |
| CVE-2026-97875 | HIGH | 8.1 | — | Sep 25, 2026 | Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebi... |
| CVE-2026-97612 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mpls: clear inner_protocol when the last label... |
| CVE-2026-97611 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix use-after-free of the flow ta... |
| CVE-2026-97609 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: cttimeout: prevent UAF during module unl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now