2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97996 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: virtio: fix use-after-free in unregister_virtio_dev... |
| CVE-2026-97995 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: virtio_console: do not free control-out buffers on ... |
| CVE-2026-97994 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vhost/vdpa: reject VRING_NUM larger than device max... |
| CVE-2026-97993 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: don't install the eventfd_ctx_fdget() e... |
| CVE-2026-97992 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: protect config_ctx from being freed und... |
| CVE-2026-97989 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vduse: validate virtqueue alignment vduse_validate... |
| CVE-2026-97988 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vhost: invalidate vring access on IOTLB transitions... |
| CVE-2026-97987 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: virtio_input: reset device if input_register_device... |
| CVE-2026-97986 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: virtio_input: stop callbacks before unregistering i... |
| CVE-2026-97985 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Update last skb marker in manage_oob(). F... |
| CVE-2026-97984 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ipv6: Fix UDP length overflow with PMTU discov... |
| CVE-2026-97983 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vduse: return compat ioctl results directly The co... |
| CVE-2026-97982 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Fix budget accounting The ... |
| CVE-2026-97981 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Count dropped frames as NAP... |
| CVE-2026-97980 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/debug: Fix NULL pointer dereference in debug_s... |
| CVE-2026-97979 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ice: add missing xa_destroy for sched_node_ids Com... |
| CVE-2026-97978 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: eth: ice: don't dereference pointers from TP_printk... |
| CVE-2026-97977 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: Fix UAF of btusb_data by rx_work ... |
| CVE-2026-97976 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: validate packet_len before... |
| CVE-2026-97975 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sysfs: Fix NULL pointer dereference ... |
| CVE-2026-97974 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: null-check fib6_node before accessing in __ip... |
| CVE-2026-97973 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: macb: destroy the phylink instance on the prob... |
| CVE-2026-97972 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: macb: put the "mdio" child node reference on s... |
| CVE-2026-97970 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: watchdog: msc313e: Avoid division by zero clk_get_... |
| CVE-2026-97969 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: watchdog: msc313e: Fix clock leak and spurious time... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now