2026 CVE Vulnerabilities
65,752 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97875 | HIGH | 8.1 | — | Sep 25, 2026 | Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebi... |
| CVE-2026-97621 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: analogix_dp: fix unchecked bound endp... |
| CVE-2026-97620 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Flush LSC untyped L1 dataport cache after r... |
| CVE-2026-97619 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: end write accounting from ->ki_complet... |
| CVE-2026-97618 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring/net: don't overconsume buffers when using ... |
| CVE-2026-97617 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Check resize_disabled before publishin... |
| CVE-2026-97616 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: release all action references o... |
| CVE-2026-97615 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: use option bits for CFM/MRP frame hand... |
| CVE-2026-97614 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: dsa: tag_brcm: legacy FCS: request needed tail... |
| CVE-2026-97613 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mana: Reserve extra CQ slot for the fence comp... |
| CVE-2026-97612 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mpls: clear inner_protocol when the last label... |
| CVE-2026-97611 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix use-after-free of the flow ta... |
| CVE-2026-97610 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix uninitialized return value in netfs_unbu... |
| CVE-2026-97609 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: cttimeout: prevent UAF during module unl... |
| CVE-2026-97608 | HIGH | 7 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: unregister loggers before per-ne... |
| CVE-2026-97607 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: vdpa: ifcvf: Put device on unsupported feature erro... |
| CVE-2026-97606 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs: autofs: fix memory leak in autofs_fill_super() ... |
| CVE-2026-97605 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: erofs: preserve LZMA decoders on resize failure Th... |
| CVE-2026-97604 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: fbdev: vfb: defer cleanup until the last reference ... |
| CVE-2026-97603 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: idpf: disable DIM work before freeing q_vectors id... |
| CVE-2026-97602 | HIGH | 7.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: inet: frags: invalidate queues before flushing them... |
| CVE-2026-97601 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ieee802154: 6lowpan: fix NULL dereference in lowpan... |
| CVE-2026-97600 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ieee802154: cc2520: fix FIFOP work use-after-free ... |
| CVE-2026-97599 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ieee802154: hwsim: serialize pib updates to fix dou... |
| CVE-2026-97598 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: bound automatic table ID allocation fib... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now