2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89968 | HIGH | 7.5 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: reject unsolicited H2CData PDUs nvmet_t... |
| CVE-2026-89967 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: avoid out-of-bounds writes for c... |
| CVE-2026-89965 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: reject an arena whose nfree is below th... |
| CVE-2026-89961 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: fix wrong addr_pfn tracking in compound... |
| CVE-2026-89960 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix stale pqap_hook pointer on error ... |
| CVE-2026-89959 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix control domain removal in vfio_ap... |
| CVE-2026-89957 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix hot-unplug skipped when last AP a... |
| CVE-2026-89954 | HIGH | 8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: mtd: afs: validate v2 image info bounds The AFS v2... |
| CVE-2026-89951 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix stale receive device on merged frag... |
| CVE-2026-89947 | HIGH | 8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: clk: meson: align gxbb_32k_clk_sel number of parent... |
| CVE-2026-89943 | HIGH | 8.4 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: loongson: Fix error handling in ACPI property... |
| CVE-2026-89942 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Fix potential use-after-free in anonym... |
| CVE-2026-89941 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Make IIO DMA fence release RCU-safe T... |
| CVE-2026-89940 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Tie IIO dma fence lock lifetime to the... |
| CVE-2026-89938 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: iio: chemical: atlas-sensor: use iio_trigger_poll_n... |
| CVE-2026-89932 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Always flush vpid02 on first use Make s... |
| CVE-2026-89929 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVM: Ensure INVVPID is emulated on the correct... |
| CVE-2026-89928 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Consume the locked rmap value in the ... |
| CVE-2026-89927 | HIGH | 7.1 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Clamp stimer deadline to avoid l... |
| CVE-2026-89922 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data... |
| CVE-2026-89920 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix memory corruption by not reinjecting... |
| CVE-2026-89919 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: keyop: use mmu_lock to read gmap->asce ... |
| CVE-2026-89913 | HIGH | 8.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v3: take an LPI reference in vgic_... |
| CVE-2026-89912 | HIGH | 7.1 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Don't dereference a NULL coll... |
| CVE-2026-89911 | HIGH | 7.9 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly cap TLBI Range to the architu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now