2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-78155CRITICAL9.9privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privi...
CVE-2026-13598CRITICAL9.8The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, al...
CVE-2026-78050CRITICAL9.9A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-b...
CVE-2026-74730CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STAT...
CVE-2026-74727CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by...
CVE-2026-74723CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid hea...
CVE-2026-74712CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys(...
CVE-2026-74705CRITICAL10In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segment...
CVE-2026-74688CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being ...
CVE-2026-74669CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP...
CVE-2026-74665CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: net: fix skb length accounting after generic XDP fr...
CVE-2026-74662CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: inet: frags: publish queues before arming timer in...
CVE-2026-74628CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by its ti...
CVE-2026-74617CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: dibs: initialise dibs->lock in dibs_dev_alloc() di...
CVE-2026-74616CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xdp: reject clones that overrun skb_shared_info tai...
CVE-2026-74612CRITICAL10In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adju...
CVE-2026-74611CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: tls: rx: restore msg_iter before TLS 1.3 optimistic...
CVE-2026-74608CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_try_adding_...
CVE-2026-74597CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip...
CVE-2026-74591CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index bef...
CVE-2026-74588CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list i...
CVE-2026-74587CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk ad...
CVE-2026-74586CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sct...
CVE-2026-4703CRITICAL9.8The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all ve...
CVE-2026-77992CRITICAL9.5Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateCommen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now