2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90176 | HIGH | 8.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Do not skip lock checks for single-byte rang... |
| CVE-2026-90174 | HIGH | 7.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_u... |
| CVE-2026-90172 | HIGH | 7.5 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: destroy QP before mem pools on acce... |
| CVE-2026-90162 | HIGH | 8.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer publishing granted locks to prevent UA... |
| CVE-2026-90161 | HIGH | 7.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced ztailpacking pclusters On-di... |
| CVE-2026-90153 | HIGH | 8.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound smb_check_perm_dacl() ACE walks by DAC... |
| CVE-2026-90149 | HIGH | 7.5 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: fix NULL dereference for NFSv4.0 d... |
| CVE-2026-90146 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf, xdp: move offload check into dev_xdp_install()... |
| CVE-2026-90145 | HIGH | 7.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: hinic3: Fix skb linearization mismatch and drop skb... |
| CVE-2026-90143 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF pars... |
| CVE-2026-90142 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix resize of the RX ring When a AF_XD... |
| CVE-2026-90141 | HIGH | 7.3 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipvs: fix integer overflow in ftp helper port/addre... |
| CVE-2026-90137 | HIGH | 7.7 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix password encoding bou... |
| CVE-2026-90133 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix index_root heap OOB write in ntfs_ir_to_i... |
| CVE-2026-90132 | HIGH | 7.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: reject unprivileged writes to reserved $LX* x... |
| CVE-2026-90131 | HIGH | 7.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: serialize resident iomap reads with mrec_lock... |
| CVE-2026-90120 | HIGH | 8.4 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v5: Check get_logical_index() return va... |
| CVE-2026-90118 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one page overflow in ntfs_decompre... |
| CVE-2026-90111 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6mr: do not clone dst in ip6mr_cache_report() IP... |
| CVE-2026-90103 | HIGH | 7.5 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: fix LAYOUTSTATS send buffer exhaustion en... |
| CVE-2026-90102 | HIGH | 7.5 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: key the data server cache on the NFS ve... |
| CVE-2026-90093 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/s... |
| CVE-2026-90092 | HIGH | 8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject accept queue add unless BT... |
| CVE-2026-90091 | HIGH | 8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix race l2cap_sock_cleanup_liste... |
| CVE-2026-90089 | HIGH | 7.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Validate the FW dump header l... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now