2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93095 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: validate thread record before delete key r... |
| CVE-2026-93079 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Get Feature count larger than ... |
| CVE-2026-93074 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: use __va(phys) for kaddr in direct_acces... |
| CVE-2026-93070 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: ipu6: Do not free aux device pdata after ini... |
| CVE-2026-93063 | HIGH | 8.4 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: check SAP message length before... |
| CVE-2026-93054 | HIGH | 7 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: uio: Fix stale info pointer in failed registration ... |
| CVE-2026-93046 | HIGH | 7 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: software node: Fix software_node_get_reference_args... |
| CVE-2026-93045 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject arena frees below the arena base bpf_a... |
| CVE-2026-93042 | HIGH | 8.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Terminate all descriptors witho... |
| CVE-2026-93039 | HIGH | 7.4 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: Keep link pointers valid on realloc fa... |
| CVE-2026-93037 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_... |
| CVE-2026-92980 | HIGH | 7.2 | 0.5% | Sep 17, 2026 | HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrato... |
| CVE-2026-92525 | HIGH | 7.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing ... |
| CVE-2026-92522 | HIGH | 7.3 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds ... |
| CVE-2026-92518 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall... |
| CVE-2026-92511 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destr... |
| CVE-2026-92510 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destr... |
| CVE-2026-92508 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_free_... |
| CVE-2026-92507 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_deall... |
| CVE-2026-92504 | HIGH | 7 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: thermal: intel: int3400: clean up ODVP on probe fai... |
| CVE-2026-92488 | HIGH | 7 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: complete object teardown when the destr... |
| CVE-2026-92485 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The t... |
| CVE-2026-90435 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix integer overflow of user QP buffer s... |
| CVE-2026-90429 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Synchronize the error ISR aga... |
| CVE-2026-90427 | HIGH | 7.4 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed sm... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now