2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90071 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_teql: restore skb->dev on the slave ... |
| CVE-2026-90069 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: acomp - allocate async request context when... |
| CVE-2026-90067 | HIGH | 7.5 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: validate banner payload length When parsi... |
| CVE-2026-90062 | HIGH | 7.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: move hardware offload step af... |
| CVE-2026-90059 | HIGH | 7.5 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: restore NET_IP_ALIGN in the RX DMA off... |
| CVE-2026-90057 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: slip: remove slip_hangup() to fix use-after-free in... |
| CVE-2026-90052 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix buffer overflow with keyed discar... |
| CVE-2026-90051 | HIGH | 7.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: reject non zerocopy devmem tx Devmem tcp tx d... |
| CVE-2026-54583 | HIGH | 8.3 | — | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-d... |
| CVE-2026-54581 | HIGH | 8.3 | — | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c... |
| CVE-2026-54580 | HIGH | 8.3 | 0.3% | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or fail... |
| CVE-2026-28326 | HIGH | 8.8 | — | Sep 17, 2026 | SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. ... |
| CVE-2026-93014 | HIGH | 7.1 | 0.4% | Sep 17, 2026 | RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing ... |
| CVE-2026-89036 | HIGH | 8.8 | 0.7% | Sep 17, 2026 | Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write ... |
| CVE-2026-86864 | HIGH | 8.8 | 0.4% | Sep 17, 2026 | pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the p... |
| CVE-2026-86040 | HIGH | 7.5 | 0.7% | Sep 17, 2026 | libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthe... |
| CVE-2026-86039 | HIGH | 8.2 | 0.3% | Sep 17, 2026 | libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in pa... |
| CVE-2026-86038 | HIGH | 7.5 | — | Sep 17, 2026 | libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses t... |
| CVE-2026-85721 | HIGH | 7.5 | — | Sep 17, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2026-85719 | HIGH | 7.5 | 0.4% | Sep 17, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2026-85715 | HIGH | 7.5 | — | Sep 17, 2026 | ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ... |
| CVE-2026-81516 | HIGH | 7.5 | — | Sep 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-81515 | HIGH | 7.5 | 0.6% | Sep 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-76834 | HIGH | 8.1 | 0.8% | Sep 17, 2026 | b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array obje... |
| CVE-2026-69197 | HIGH | 8.7 | — | Sep 17, 2026 | Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Acce... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now