2026 CVE Vulnerabilities
67,095 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97423 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: cxl/region: Validate partition index before array a... |
| CVE-2026-97422 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix SMI event cross-process information... |
| CVE-2026-97421 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Be careful about boundary conditions in ... |
| CVE-2026-97420 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: NUL-terminate replaced sysctl value When writ... |
| CVE-2026-97419 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: hsr: broadcast netlink notifications in the device'... |
| CVE-2026-97418 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: es18xx: check control allocation before priva... |
| CVE-2026-97417 | HIGH | 7.5 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() i... |
| CVE-2026-97416 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: balance: fix potential bg lookup failure in ... |
| CVE-2026-97415 | HIGH | 7.8 | 0.1% | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: tree-checker: validate names in ROOT_REF and... |
| CVE-2026-97414 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8365-afe-pcm: fix possible NULL-p... |
| CVE-2026-97413 | CRITICAL | 9.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_rea... |
| CVE-2026-97412 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: pds_core: quiesce DMA before freeing resources pds... |
| CVE-2026-97411 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ibm: emac: mal: fix potential system hang in m... |
| CVE-2026-97410 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netconsole: take target_cleanup_list_lock in drop_n... |
| CVE-2026-97409 | HIGH | 8.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Do not cancel requests in io target before... |
| CVE-2026-97408 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate connectionless PSM lengt... |
| CVE-2026-97407 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: rockchip: rockchip_pdm: Handle runtime PM res... |
| CVE-2026-97231 | HIGH | 7.3 | — | Sep 24, 2026 | A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py o... |
| CVE-2026-94613 | HIGH | 7.5 | — | Sep 24, 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker ca... |
| CVE-2026-94612 | HIGH | 7.4 | — | Sep 24, 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verif... |
| CVE-2026-94611 | HIGH | 8.1 | — | Sep 24, 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers retu... |
| CVE-2026-94609 | HIGH | 8.8 | — | Sep 24, 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated perm... |
| CVE-2026-94606 | HIGH | 8.9 | — | Sep 24, 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator ... |
| CVE-2026-94604 | — | — | — | Sep 24, 2026 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2026-94281 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X se... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now