2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-68443 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (gigabyte_waterforce) Stop device IO before ... |
| CVE-2026-68442 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_FLAG_LOGGING to split... |
| CVE-2026-68441 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: Handle TC_ACT_REDIRECT from qdisc filter... |
| CVE-2026-68440 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix heap overflow when reading module E... |
| CVE-2026-68439 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix possible NULL-pointer deref... |
| CVE-2026-68438 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: smp: Make CSD lock acquisition atomic for debug mod... |
| CVE-2026-68437 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fit paired fragment job in the cor... |
| CVE-2026-68436 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: use kvzalloc to allocate struct dc... |
| CVE-2026-68435 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix address space mismatch in kexec comm... |
| CVE-2026-68434 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250_mid: Fix NULL function pointer derefer... |
| CVE-2026-68433 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front le... |
| CVE-2026-68432 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns fo... |
| CVE-2026-68431 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requ... |
| CVE-2026-68430 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessary BUG_ON() There's ... |
| CVE-2026-68429 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Handle torn-down topology gracefully in... |
| CVE-2026-19559 | — | — | — | Aug 11, 2026 | Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code insi... |
| CVE-2026-71290 | — | — | — | Aug 11, 2026 | Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolic... |
| CVE-2026-18634 | — | — | — | Aug 11, 2026 | An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (B... |
| CVE-2026-69223 | — | — | — | Aug 11, 2026 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before... |
| CVE-2026-6727 | — | — | — | Aug 11, 2026 | A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a... |
| CVE-2026-6726 | — | — | — | Aug 11, 2026 | An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker wi... |
| CVE-2026-51584 | — | — | — | Aug 11, 2026 | An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the S... |
| CVE-2026-51583 | — | — | — | Aug 11, 2026 | An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF... |
| CVE-2026-14549 | — | — | — | Aug 11, 2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ... |
| CVE-2026-14548 | — | — | — | Aug 11, 2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now