2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90171 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: release pending child sockets outsi... |
| CVE-2026-90170 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ipc response length before derefere... |
| CVE-2026-90169 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: free preauth sessions on connection teardown... |
| CVE-2026-90168 | — | — | — | Sep 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-90167 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize oplock close with pending break ow... |
| CVE-2026-90166 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix null-ptr-deref in ksmbd_ipc_tree_co... |
| CVE-2026-90165 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix invalid pointer dereference in ksmb... |
| CVE-2026-90164 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: abort initialization when proc setup fa... |
| CVE-2026-90163 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_proc_cleanup() on module ini... |
| CVE-2026-90160 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: lwt_bpf: Restore reserved headroom after xmit progr... |
| CVE-2026-90159 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX g... |
| CVE-2026-90158 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in... |
| CVE-2026-90157 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt ho... |
| CVE-2026-90156 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely discard unregistered deferred locks ... |
| CVE-2026-90155 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: detach blocked lock requests before freeing ... |
| CVE-2026-90154 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope session state changes to bound connect... |
| CVE-2026-90152 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_regis... |
| CVE-2026-90150 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: pnfs/blocklayout: Fix device leaks on parse failure... |
| CVE-2026-90148 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix incorrect argument passed to nfs4_delete... |
| CVE-2026-90147 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: clk: devres: fix cleanup in devm_clk_get_optional_e... |
| CVE-2026-90144 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: dpll: fix NULL deref in dpll_device_ops() during te... |
| CVE-2026-90140 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: cuse: wait for pending RCU callbacks on module exit... |
| CVE-2026-90139 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: fuse: check for NULL root inode in fuse_fill_super_... |
| CVE-2026-90138 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: vsock: don't check the listener's sk_err in vsock_a... |
| CVE-2026-90136 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/hsmp: Reject negative power cap wr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now