2026 CVE Vulnerabilities
65,702 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-98049 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: zero extend the result of an arena 32-bit cmpx... |
| CVE-2026-98048 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: don't rewrite bpf_fastcall patterns entered by... |
| CVE-2026-98047 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Check ancestor frames for rbtree callbacks bp... |
| CVE-2026-98046 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_btf_find_by_name_kind() as sleepable ... |
| CVE-2026-98045 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark faultable stack helpers as sleepable The... |
| CVE-2026-98044 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject legacy packet loads from callbacks che... |
| CVE-2026-98043 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Don't infer non-NULL from a pointer with an un... |
| CVE-2026-98042 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Don't resurrect a scalar id dropped by collect... |
| CVE-2026-98041 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Don't predict JMP32 pointer vs zero comparison... |
| CVE-2026-98040 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark the zero register precise for a register-... |
| CVE-2026-98039 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Require MEM_PERCPU for percpu kptr stores map... |
| CVE-2026-98038 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Keep refcount_acquire nullable for borrowed RC... |
| CVE-2026-98037 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject untrusted allocated-object pointers Wh... |
| CVE-2026-98036 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve special fields in recycled rhtab elem... |
| CVE-2026-98035 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Cancel special fields when recycling rhtab ele... |
| CVE-2026-98034 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark NULL kptr stores precise check_map_kptr_... |
| CVE-2026-98033 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve inner map identity in callback frames... |
| CVE-2026-98032 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix subbuf resize races with trace_pipe_ra... |
| CVE-2026-98031 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nexthop: Initialize extack in remove_nh_grp_entry()... |
| CVE-2026-98030 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: dsa: bcm_sf2: bound the CFP rule dump by the c... |
| CVE-2026-98029 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: eth: nfp: bound the ntuple rule dump by the caller'... |
| CVE-2026-98028 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: eth: nfp: drop the replaced rule from the list when... |
| CVE-2026-98027 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: bound the policy rule dump by ... |
| CVE-2026-98026 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: properly convert mglist to rcu ... |
| CVE-2026-98025 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: usb: cx82310_eth: drop URB after 0xffff reboot... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now