2026 CVE Vulnerabilities
65,724 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97920 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Keep the entry count when the histogram st... |
| CVE-2026-97919 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Take the reference before publishing the n... |
| CVE-2026-97918 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Undo the registration when enabling the hi... |
| CVE-2026-97917 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Validate full buffer range in ivpu_to_c... |
| CVE-2026-97916 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Validate firmware log buffer metadata ... |
| CVE-2026-97915 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Limit firmware log name prints to field... |
| CVE-2026-97914 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Fix ethosu_job_open() return value ... |
| CVE-2026-97913 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure cmd stream ends with a stop o... |
| CVE-2026-97912 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure SRAM size is 0 on mapping fai... |
| CVE-2026-97911 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure SRAM region size matches job ... |
| CVE-2026-97910 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: sprd: validate compress buffer sizes against ... |
| CVE-2026-97909 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: sti: initialize IRQ lock before requesting IR... |
| CVE-2026-97908 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btqcomsmd: destroy RPMsg endpoints befor... |
| CVE-2026-97907 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Don't leak return code when parsi... |
| CVE-2026-97906 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bootconfig: Fix integer overflow in initrd size che... |
| CVE-2026-97905 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: zero-initialize policy cpumask before sysf... |
| CVE-2026-97904 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: initialize policy rwsem before sysfs publi... |
| CVE-2026-97903 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: exit: hold a reference to thread_pid across proc_fl... |
| CVE-2026-97902 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs: don't return -EINVAL for successful nested thaw... |
| CVE-2026-97901 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: genetlink: pin family module during policy dump Th... |
| CVE-2026-97900 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/drm_exec: fix up contended obj when num_objects... |
| CVE-2026-97899 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix memory leak in query_perf_config_list... |
| CVE-2026-97875 | HIGH | 8.1 | — | Sep 25, 2026 | Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebi... |
| CVE-2026-97621 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: analogix_dp: fix unchecked bound endp... |
| CVE-2026-97620 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Flush LSC untyped L1 dataport cache after r... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now