2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73166 | HIGH | 8.6 | 0.7% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the... |
| CVE-2026-73165 | HIGH | 8.6 | 1.0% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-73164 | HIGH | 8.6 | 0.9% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-73163 | HIGH | 8.6 | 0.9% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-19535 | HIGH | 8.6 | 0.2% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative we... |
| CVE-2026-92465 | HIGH | 7.6 | 0.3% | Sep 16, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Me... |
| CVE-2026-92456 | HIGH | 7.1 | 0.4% | Sep 16, 2026 | yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerContr... |
| CVE-2026-40857 | HIGH | 8.4 | — | Sep 16, 2026 | WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. T... |
| CVE-2026-40856 | HIGH | 7.1 | — | Sep 16, 2026 | WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cg... |
| CVE-2026-40854 | HIGH | 8.7 | — | Sep 16, 2026 | WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session ... |
| CVE-2026-90047 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't hand out the flat CCS storage as usab... |
| CVE-2026-90046 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP P... |
| CVE-2026-90045 | HIGH | 7.8 | 0.1% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_data... |
| CVE-2026-90044 | HIGH | 7.8 | 0.1% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-After-Free in AIO error ... |
| CVE-2026-90043 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: zram: fix slot lock bit position on big-endian 64-b... |
| CVE-2026-90041 | HIGH | 8.8 | 0.3% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: sony: clean up device list on probe failure s... |
| CVE-2026-90032 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: usbtv: keep device alive while ALSA card exi... |
| CVE-2026-90030 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: clear forceRM when issuing EndTransfer ... |
| CVE-2026-90027 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic-typec: disable cc_debounce_dw... |
| CVE-2026-90026 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic: cancel reset_work on stop p... |
| CVE-2026-90025 | HIGH | 7.7 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix OOB altmode arra... |
| CVE-2026-90022 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-after-free in string ... |
| CVE-2026-90018 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read / stack overflow i... |
| CVE-2026-90017 | HIGH | 7.1 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_fram... |
| CVE-2026-90016 | HIGH | 7.1 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wm... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now