2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47153 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-ze... |
| CVE-2026-47152 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-ze... |
| CVE-2026-47149 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table re... |
| CVE-2026-47148 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the me... |
| CVE-2026-47146 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ... |
| CVE-2026-47145 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ... |
| CVE-2026-42390 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured wit... |
| CVE-2026-42389 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative ... |
| CVE-2026-42388 | MEDIUM | 5.9 | 0.4% | Jun 25, 2026 | Incomplete validation of the SOA record present in a catalog zone might lead to a crash. |
| CVE-2026-42387 | MEDIUM | 5.9 | 0.4% | Jun 25, 2026 | A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recur... |
| CVE-2026-40012 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have... |
| CVE-2026-40211 | MEDIUM | 5.3 | 0.4% | Jun 25, 2026 | An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed... |
| CVE-2026-40210 | MEDIUM | 4.8 | 0.3% | Jun 25, 2026 | An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being se... |
| CVE-2026-40209 | MEDIUM | 5.3 | 0.4% | Jun 25, 2026 | An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of bei... |
| CVE-2026-42005 | MEDIUM | 4.3 | 0.5% | Jun 25, 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a den... |
| CVE-2026-54226 | MEDIUM | 6.4 | 0.3% | Jun 25, 2026 | A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended... |
| CVE-2026-53274 | MEDIUM | 5.5 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix sleep-inside-lock in __smc_setsockopt(... |
| CVE-2026-53271 | MEDIUM | 5.5 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix NULL-deref of opinfo->conn in oplock/lea... |
| CVE-2026-53269 | MEDIUM | 5.5 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: add mutex to guard hook refere... |
| CVE-2026-53263 | MEDIUM | 5.5 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix off-by-one in multicast context addres... |
| CVE-2026-53258 | MEDIUM | 5.5 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: fix leak if split 6 GHz scanning fails rdev-... |
| CVE-2026-53257 | MEDIUM | 5.5 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: enforce HE/EHT cap/oper consistency... |
| CVE-2026-53252 | MEDIUM | 5.5 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix memory leak in error path of hci_all... |
| CVE-2026-53251 | MEDIUM | 5.5 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not releasing hdev reference on... |
| CVE-2026-53249 | MEDIUM | 5.5 | 0.2% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options T... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now