2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93233 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dmem: fix callocated underflow on large... |
| CVE-2026-93232 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and... |
| CVE-2026-93231 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: lockd: fix swapped arguments in nlmsvc_match_ip() ... |
| CVE-2026-93230 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: initialize gigantic bootmem hugepage st... |
| CVE-2026-93227 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/mm_init: deferred_grow_zone(): fix out-of-range ... |
| CVE-2026-93226 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU iterator to dump route exceptions rt... |
| CVE-2026-93223 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: media: tegra-video: fix of_node_put() on V... |
| CVE-2026-93222 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: signal: avoid shared siginfo namespace rewrites se... |
| CVE-2026-93220 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Keep kick_sync waiting on the rq's own C... |
| CVE-2026-93219 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sun4i: Advertise a real m... |
| CVE-2026-93218 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: skip device-private PMDs in madvise... |
| CVE-2026-93217 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/madvise: skip device-private PMDs in cold and pa... |
| CVE-2026-93216 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/page_owner: use memcg_data snapshot to avoid TOC... |
| CVE-2026-93215 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: cdx: Fix double free when sysfs file creation fails... |
| CVE-2026-93214 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()... |
| CVE-2026-93213 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: of: fix out-of-bounds read in of_alias_scan() stem ... |
| CVE-2026-93212 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: guard nfsd_serv deref in nfsd_file_net_dispos... |
| CVE-2026-93211 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize DRC hash table before registering ... |
| CVE-2026-93210 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: harden DFS cache against invalid targe... |
| CVE-2026-93209 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: use skb_get() instead of skb_c... |
| CVE-2026-93208 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: kasan: fix cache shrink race with CPU hotplug kasa... |
| CVE-2026-93206 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: PCI/proc: Use file_ns_capable() when checking confi... |
| CVE-2026-93205 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Manage teardown with devm arm_s... |
| CVE-2026-88371 | — | — | — | Sep 24, 2026 | ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing sp... |
| CVE-2026-88366 | — | — | — | Sep 24, 2026 | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG ar... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now