2026 CVE Vulnerabilities

64,616 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45858MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: don't zero the entire extent if EXT4_EXT_DATA...
CVE-2026-45857MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: csiostor: Fix dereference of null pointer rn ...
CVE-2026-45856HIGH7.1In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Validate wqe_size before using it in i...
CVE-2026-45855MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ata: libata-scsi: avoid Non-NCQ command starvation ...
CVE-2026-45854MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: inside-secure/eip93 - unregister only avail...
CVE-2026-45853HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Use kvfree instead of kfree in amdgpu_g...
CVE-2026-45852HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix double free in rxe_srq_from_init In ...
CVE-2026-45851HIGH7.1In the Linux kernel, the following vulnerability has been resolved: efi: Fix reservation of unaccepted memory table Th...
CVE-2026-45850MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipvs: skip ipv6 extension headers for csum checks ...
CVE-2026-45849MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: add missing lock protection in o...
CVE-2026-45848MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: apparmor: fix NULL sock in aa_sock_file_perm Deal ...
CVE-2026-45847MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: remove WARN_ON_ONCE when accessing forward pat...
CVE-2026-42791LOW3.7Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses...
CVE-2026-42789MEDIUM4.8Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows ...
CVE-2026-3676MEDIUM6.5IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (include...
CVE-2026-3623HIGH7.8IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged acces...
CVE-2026-3366HIGH7.5IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, ...
CVE-2026-38427HIGH7.3An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffe...
CVE-2026-38426HIGH7.3Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary cod...
CVE-2026-38422HIGH7.3Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary cod...
CVE-2026-36540HIGH7.3Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi end...
CVE-2026-36539HIGH7.3Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configur...
CVE-2026-36538HIGH7.3Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password fo...
CVE-2026-36045HIGH7.3picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The...
CVE-2026-36044HIGH8.8@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool(...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now