2026 CVE Vulnerabilities

55,512 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-64217HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter...
CVE-2026-64216CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_...
CVE-2026-64215MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send...
CVE-2026-64214MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: powerpc/time: Remove redundant preempt_disable|enab...
CVE-2026-64213MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Add lock protection to lm90_alert Sa...
CVE-2026-64212MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: don't dereference a pointer bef...
CVE-2026-64211MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: srcu: Don't queue workqueue handlers to never-onlin...
CVE-2026-64210HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ Duri...
CVE-2026-64209HIGH7.1In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access...
CVE-2026-64208HIGH7.5In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-ver...
CVE-2026-17039LOW3.1A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based autho...
CVE-2026-8789HIGH8.1The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2026-8308MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa...
CVE-2026-7007MEDIUM4.6The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl....
CVE-2026-66007MEDIUM6.5Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder...
CVE-2026-66006MEDIUM6.9lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs...
CVE-2026-66005MEDIUM6.3Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that ...
CVE-2026-66004MEDIUM6BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all...
CVE-2026-58630CRITICAL9.8Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58586CRITICAL9.8Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the sys...
CVE-2026-57106CRITICAL10Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56163CRITICAL10Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el...
CVE-2026-55732HIGH8.7Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-R...
CVE-2026-55731MEDIUM6.6Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI...
CVE-2026-55730HIGH8.7Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now