2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90061 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: skip double clone set express... |
| CVE-2026-90060 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Don't add invalid kcontrols to LED l... |
| CVE-2026-90058 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: bound qdisc_pkt_len to prevent qdisc sof... |
| CVE-2026-90056 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: fec: only stop PTP if it was initialized fec_... |
| CVE-2026-90055 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: atm: usbatm: fix invalid ci_range initializati... |
| CVE-2026-90054 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix corruption of urgent data on multi-segment... |
| CVE-2026-90053 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_htb: limit htb_classify inner-class ... |
| CVE-2026-90050 | — | — | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: clamp quantum and initial_quantum in... |
| CVE-2026-53681 | — | — | — | Sep 17, 2026 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. |
| CVE-2026-53679 | — | — | — | Sep 17, 2026 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. |
| CVE-2026-11874 | — | — | — | Sep 17, 2026 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. |
| CVE-2026-85789 | — | — | — | Sep 16, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-92571 | — | — | — | Sep 16, 2026 | Rejected reason: CVE ID reserved in error and not assigned to a vulnerability. The correct CVE ID is CVE-2026-92574. |
| CVE-2026-90040 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Forcefully invalidate SNP VMSA if its bac... |
| CVE-2026-90039 | — | — | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Guard admin state-revocation walks with NFSD_... |
| CVE-2026-90035 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix division by zero in get_estima... |
| CVE-2026-90034 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: image: mdc800: change kmalloc() to kzalloc() ... |
| CVE-2026-90033 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_us122... |
| CVE-2026-90031 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb-storage: ene_ub6250: fix race between scan work... |
| CVE-2026-90029 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: storage: realtek_cr: fix use-after-free on dis... |
| CVE-2026-90028 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: hd3ss3220: track VBUS enable state per ... |
| CVE-2026-90024 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: midi2: Fix null-pointer dereference in... |
| CVE-2026-90023 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: fix null pointer deref... |
| CVE-2026-90021 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_allo... |
| CVE-2026-90020 | — | — | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: USB: gadget: fix NULL pointer dereference in gadget... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now