2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90042 | CRITICAL | 9.8 | 0.5% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filenames in vmalloc() buffe... |
| CVE-2026-90038 | CRITICAL | 9.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during export s... |
| CVE-2026-90037 | CRITICAL | 9.8 | 0.5% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lr... |
| CVE-2026-90036 | CRITICAL | 9.8 | 0.5% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during blocked-... |
| CVE-2026-90012 | CRITICAL | 9.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failu... |
| CVE-2026-90011 | CRITICAL | 9.1 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for ... |
| CVE-2026-89990 | CRITICAL | 9.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: lock mutex in ceph_mds_check_access() MDS se... |
| CVE-2026-89972 | CRITICAL | 9.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path ... |
| CVE-2026-89970 | CRITICAL | 9.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ tear... |
| CVE-2026-89969 | CRITICAL | 9.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving a... |
| CVE-2026-89930 | CRITICAL | 9.3 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Service local TLB flushes on failed nest... |
| CVE-2026-89918 | CRITICAL | 9.3 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly handle end of VA space TLBI i... |
| CVE-2026-89916 | CRITICAL | 9.3 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make VNCR invalidation participate in M... |
| CVE-2026-89915 | CRITICAL | 9.3 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Remove VM-wide VNCR mapping counter Th... |
| CVE-2026-89914 | CRITICAL | 9.3 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI inv... |
| CVE-2026-89857 | CRITICAL | 9.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS... |
| CVE-2026-89847 | CRITICAL | 9.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOC... |
| CVE-2026-89846 | CRITICAL | 9.1 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sens... |
| CVE-2026-86106 | CRITICAL | 9.6 | — | Sep 16, 2026 | An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions with... |
| CVE-2026-76187 | CRITICAL | 9.8 | 0.2% | Sep 16, 2026 | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confiden... |
| CVE-2026-76186 | CRITICAL | 9.1 | 0.2% | Sep 16, 2026 | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Air... |
| CVE-2026-73453 | CRITICAL | 10 | 0.7% | Sep 16, 2026 | An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary c... |
| CVE-2026-89788 | CRITICAL | 9.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_t... |
| CVE-2026-89786 | CRITICAL | 9.1 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_di... |
| CVE-2026-89783 | CRITICAL | 9.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr(... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now