2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12394 | CRITICAL | 9.8 | — | Jul 27, 2026 | The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing ... |
| CVE-2026-64530 | CRITICAL | 9.8 | 0.2% | Jul 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_q... |
| CVE-2026-66013 | CRITICAL | 9.3 | 0.4% | Jul 25, 2026 | OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows una... |
| CVE-2026-66012 | CRITICAL | 10 | 0.4% | Jul 25, 2026 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated onl... |
| CVE-2026-64523 | CRITICAL | 9.8 | 0.3% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at ... |
| CVE-2026-64459 | CRITICAL | 9.8 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_soc... |
| CVE-2026-64450 | CRITICAL | 9.1 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap ACK b... |
| CVE-2026-64439 | CRITICAL | 9.8 | 0.4% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implementation... |
| CVE-2026-64410 | CRITICAL | 9.8 | 0.4% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: IPIP tunnel hardware offload ... |
| CVE-2026-64399 | CRITICAL | 9.8 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EX... |
| CVE-2026-64397 | CRITICAL | 9.8 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file ... |
| CVE-2026-64393 | CRITICAL | 9.1 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 S... |
| CVE-2026-64392 | CRITICAL | 9.1 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close ... |
| CVE-2026-64391 | CRITICAL | 9.8 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternat... |
| CVE-2026-64387 | CRITICAL | 9.8 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free... |
| CVE-2026-64386 | CRITICAL | 9.8 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A... |
| CVE-2026-64385 | CRITICAL | 9.8 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay... |
| CVE-2026-64384 | CRITICAL | 9.8 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free ... |
| CVE-2026-64383 | CRITICAL | 9.8 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay... |
| CVE-2026-64355 | CRITICAL | 9.8 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap bro... |
| CVE-2026-64320 | CRITICAL | 9.1 | 0.7% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Disc... |
| CVE-2026-64319 | CRITICAL | 9.1 | 0.5% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds a... |
| CVE-2026-64303 | CRITICAL | 9.8 | 0.7% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prep... |
| CVE-2026-64269 | CRITICAL | 9.1 | 0.7% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk siz... |
| CVE-2026-64268 | CRITICAL | 9.8 | 0.7% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREA... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now