2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90279 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: md/raid5: round bitmap stripes with sector division... |
| CVE-2026-90278 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: md: wait for behind writes before destroying bitmap... |
| CVE-2026-90277 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: prevent create failure bitmap UAF ... |
| CVE-2026-90276 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: stop daemon timer rearm on destroy ... |
| CVE-2026-90275 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: md/raid1: don't set array_frozen in raid1_takeover(... |
| CVE-2026-90274 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: coresight: etm4x: fix underflow for usage of (nrseq... |
| CVE-2026-90273 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: coresight: etm4x: missing cscfg_csdev_disable_activ... |
| CVE-2026-90272 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf: arm_pmuv3: Zero initialize hw_id branch stack... |
| CVE-2026-90271 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Fix a NULL pointer dereference on unbindi... |
| CVE-2026-90270 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Disable driver unbind to avoid UAF When ... |
| CVE-2026-90269 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject load-acquire from pointers requiring fa... |
| CVE-2026-90267 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix special_vec mempool leak when scsi_al... |
| CVE-2026-90266 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: don't force read-only on transient -E... |
| CVE-2026-90265 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: defrag: fix deadlock between defrag and dela... |
| CVE-2026-90264 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: always wait for ordered extents to avoid OE ... |
| CVE-2026-90263 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: check if root is readonly when setting posix... |
| CVE-2026-90262 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: retry verity reads for not-uptodate Merkle f... |
| CVE-2026-90261 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: flush active metadata block group at ... |
| CVE-2026-90259 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix a wrong length calculation in qg... |
| CVE-2026-90258 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: airoha: add missed IRQ resource helpers W... |
| CVE-2026-90257 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: avoid OOB read of build info ... |
| CVE-2026-90254 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: free the advertising instance ... |
| CVE-2026-90253 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the mesh send cancel command ... |
| CVE-2026-90252 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the HCI command when it is ca... |
| CVE-2026-90251 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MSFT: validate evt_prefix_len against th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now