2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93806 | HIGH | 8.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate assoc response length befo... |
| CVE-2026-93801 | HIGH | 7 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: zero-initialize stack-allocated cifs_op... |
| CVE-2026-93799 | HIGH | 8.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: validate sta_id in BA window st... |
| CVE-2026-93798 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reloc root cleanup in merge_reloc_roots(... |
| CVE-2026-93796 | HIGH | 7 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: pcie: null RX pointers after free W... |
| CVE-2026-93793 | HIGH | 8.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: validate TX_CMD response layout... |
| CVE-2026-93790 | HIGH | 8.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix out-of-bounds tid_data acce... |
| CVE-2026-93787 | HIGH | 8.1 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: bound dirent name against end of SMB r... |
| CVE-2026-93786 | HIGH | 8.1 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The V... |
| CVE-2026-93782 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhos... |
| CVE-2026-93543 | HIGH | 7.4 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an... |
| CVE-2026-93288 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period... |
| CVE-2026-93287 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized block transfers in the... |
| CVE-2026-93284 | HIGH | 8.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migrat... |
| CVE-2026-91160 | HIGH | 8.2 | — | Sep 24, 2026 | OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers... |
| CVE-2026-91123 | HIGH | 7.2 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src tra... |
| CVE-2026-91122 | HIGH | 8.7 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placehol... |
| CVE-2026-88390 | HIGH | 7.7 | — | Sep 24, 2026 | An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted Java... |
| CVE-2026-88382 | HIGH | 7.5 | — | Sep 24, 2026 | hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate pars... |
| CVE-2026-88376 | HIGH | 7.5 | — | Sep 24, 2026 | Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A speci... |
| CVE-2026-88373 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL()... |
| CVE-2026-88372 | HIGH | 7.5 | — | Sep 24, 2026 | libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) ... |
| CVE-2026-79764 | HIGH | 7.7 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0... |
| CVE-2026-63498 | HIGH | 8.7 | — | Sep 24, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_t... |
| CVE-2026-63493 | HIGH | 8.6 | — | Sep 24, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now