2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-90042CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filenames in vmalloc() buffe...
CVE-2026-90038CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during export s...
CVE-2026-90037CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lr...
CVE-2026-90036CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during blocked-...
CVE-2026-90012CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failu...
CVE-2026-90011CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for ...
CVE-2026-89990CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ceph: lock mutex in ceph_mds_check_access() MDS se...
CVE-2026-89972CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path ...
CVE-2026-89970CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ tear...
CVE-2026-89969CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving a...
CVE-2026-89930CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Service local TLB flushes on failed nest...
CVE-2026-89918CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly handle end of VA space TLBI i...
CVE-2026-89916CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make VNCR invalidation participate in M...
CVE-2026-89915CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Remove VM-wide VNCR mapping counter Th...
CVE-2026-89914CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI inv...
CVE-2026-89857CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS...
CVE-2026-89847CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOC...
CVE-2026-89846CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sens...
CVE-2026-86106CRITICAL9.6An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions with...
CVE-2026-76187CRITICAL9.8Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confiden...
CVE-2026-76186CRITICAL9.1Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Air...
CVE-2026-73453CRITICAL10An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary c...
CVE-2026-89788CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_t...
CVE-2026-89786CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_di...
CVE-2026-89783CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr(...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now