2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89689 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: don't free session slots that are still in us... |
| CVE-2026-89688 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqi... |
| CVE-2026-89686 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on r... |
| CVE-2026-89681 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix layout fence worker double-reference race... |
| CVE-2026-89677 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix possible fh_compose of wrong dentry in nf... |
| CVE-2026-89676 | CRITICAL | 9.8 | 0.4% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async... |
| CVE-2026-89675 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix UAF in async copy cancel and shutdown An... |
| CVE-2026-89674 | CRITICAL | 9.8 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encode... |
| CVE-2026-89672 | CRITICAL | 9.1 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs2 setacl by argp->mask The NFSACL v2... |
| CVE-2026-89671 | CRITICAL | 9.1 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs3 setacl by argp->mask nfsd3_proc_se... |
| CVE-2026-89669 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy-notify stateid before publish... |
| CVE-2026-89662 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent lock owner use-after-free during clie... |
| CVE-2026-89660 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin st... |
| CVE-2026-89659 | CRITICAL | 9.8 | 0.4% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegati... |
| CVE-2026-89658 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during NFSv4.0 ... |
| CVE-2026-89656 | CRITICAL | 9.8 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: reject buckets with mismatched CRUSH ids ... |
| CVE-2026-89655 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in __kick_flushing_caps() on cf entry... |
| CVE-2026-89654 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in check_new_map() on session freed d... |
| CVE-2026-89653 | CRITICAL | 9.8 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: reject export_targets ranks >= CEPH_MAX_MDS i... |
| CVE-2026-89652 | CRITICAL | 9.8 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound copied dentry name length in NFS export... |
| CVE-2026-89651 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound MDSCapAuth path and fs_name decode in h... |
| CVE-2026-89650 | CRITICAL | 9.1 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info v... |
| CVE-2026-89649 | CRITICAL | 9.1 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound xattr value length in __build_xattrs() ... |
| CVE-2026-89643 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: audit: avoid dropping live tree ref on fsnotify rul... |
| CVE-2026-89637 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now