2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-12394CRITICAL9.8The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing ...
CVE-2026-64530CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_q...
CVE-2026-66013CRITICAL9.3OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows una...
CVE-2026-66012CRITICAL10SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated onl...
CVE-2026-64523CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at ...
CVE-2026-64459CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_soc...
CVE-2026-64450CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap ACK b...
CVE-2026-64439CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implementation...
CVE-2026-64410CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: IPIP tunnel hardware offload ...
CVE-2026-64399CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EX...
CVE-2026-64397CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file ...
CVE-2026-64393CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 S...
CVE-2026-64392CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close ...
CVE-2026-64391CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternat...
CVE-2026-64387CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free...
CVE-2026-64386CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A...
CVE-2026-64385CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay...
CVE-2026-64384CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free ...
CVE-2026-64383CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay...
CVE-2026-64355CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap bro...
CVE-2026-64320CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Disc...
CVE-2026-64319CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds a...
CVE-2026-64303CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prep...
CVE-2026-64269CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk siz...
CVE-2026-64268CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREA...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now