2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90014 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Have show_event_filters/triggers files tak... |
| CVE-2026-90013 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening op... |
| CVE-2026-90010 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Cap io_uring sense copy to max_response_... |
| CVE-2026-90009 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Fix TOCTOU in io_uring passthrough comma... |
| CVE-2026-90008 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Limit NVMe request size to the ... |
| CVE-2026-90007 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Use rollback index when freeing MSI-X... |
| CVE-2026-90003 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: futex: Prevent rcuwait use-after-free during requeu... |
| CVE-2026-90002 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ftrace: Take trace_array reference before accessing... |
| CVE-2026-90001 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: bpf: serialize device reference release in str... |
| CVE-2026-90000 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: rmi: fix OOB access with undersized RMI report... |
| CVE-2026-8462 | HIGH | 8.9 | 0.5% | Sep 16, 2026 | SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allo... |
| CVE-2026-89999 | HIGH | 8.1 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: validate report length in wacom_intuos_... |
| CVE-2026-89998 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm: fix race when loading and unloading a table If... |
| CVE-2026-89997 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm: fix resume-vs-remove race If the user issues t... |
| CVE-2026-89995 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: dma-direct: return struct page from dma_direct_allo... |
| CVE-2026-89994 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: tracing: no ptr dereference du... |
| CVE-2026-89992 | HIGH | 8.4 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: cpuidle: dt_idle_genpd: kfree() the original name a... |
| CVE-2026-89988 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: kprobes: Protect kprobe_blacklist with RCU __withi... |
| CVE-2026-89986 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: fix sleeping allocation in alloc_page... |
| CVE-2026-89985 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: memcg: keep folio's objcg same as its node memcg_r... |
| CVE-2026-89980 | HIGH | 8.4 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: harmony: initialize locks before requesting I... |
| CVE-2026-89979 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix race between non-atomic ops and trig... |
| CVE-2026-89974 | HIGH | 7.5 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-fc: fix double free of fabrics options when nv... |
| CVE-2026-89973 | HIGH | 8.2 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: check the data direction of a C2HData PDU... |
| CVE-2026-89971 | HIGH | 7.5 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme: skip the zoned limits update if the zone info... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now