2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89495 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handler... |
| CVE-2026-89494 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler ... |
| CVE-2026-89492 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when r... |
| CVE-2026-89485 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-d... |
| CVE-2026-89482 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: do not accept C2HData based on blk_rq_pay... |
| CVE-2026-89479 | CRITICAL | 9.8 | 0.4% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its association... |
| CVE-2026-89478 | CRITICAL | 9.8 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: drop a chunk if its transport was removed sc... |
| CVE-2026-89448 | CRITICAL | 9.3 | 0.1% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Force requesting ACS when tboot is enab... |
| CVE-2026-81002 | CRITICAL | 9.8 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_... |
| CVE-2026-80986 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC ... |
| CVE-2026-80981 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in sm... |
| CVE-2026-80980 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing... |
| CVE-2026-80976 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: seg6: reset IP6CB after IPv6 decapsulation decap_a... |
| CVE-2026-80945 | CRITICAL | 9.1 | 0.5% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on... |
| CVE-2026-80926 | CRITICAL | 9.8 | 0.4% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notificat... |
| CVE-2026-53952 | CRITICAL | 9.8 | 0.3% | Sep 11, 2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic f... |
| CVE-2026-52630 | CRITICAL | 9.8 | 0.5% | Sep 11, 2026 | SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEdito... |
| CVE-2026-79396 | CRITICAL | 9.8 | 0.4% | Sep 11, 2026 | Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores sta... |
| CVE-2026-79395 | CRITICAL | 9.8 | 0.4% | Sep 11, 2026 | An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia I... |
| CVE-2026-62105 | CRITICAL | 9.8 | — | Sep 11, 2026 | Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions. |
| CVE-2026-62103 | CRITICAL | 9.8 | — | Sep 11, 2026 | Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. |
| CVE-2026-54072 | CRITICAL | 9.3 | 0.3% | Sep 11, 2026 | Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/autho... |
| CVE-2026-82617 | CRITICAL | 9.8 | 0.3% | Sep 11, 2026 | The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FIND... |
| CVE-2026-72710 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attac... |
| CVE-2026-72709 | CRITICAL | 9.8 | 0.3% | Sep 11, 2026 | SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now