2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89803 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the channel-kill event bef... |
| CVE-2026-89801 | HIGH | 7.8 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix premature region free on fail... |
| CVE-2026-89799 | HIGH | 7.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_get_stackid The get... |
| CVE-2026-89795 | HIGH | 8.4 | — | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset... |
| CVE-2026-86585 | HIGH | 7.7 | — | Sep 16, 2026 | The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01... |
| CVE-2026-14916 | HIGH | 7.7 | — | Sep 16, 2026 | A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit... |
| CVE-2026-89793 | HIGH | 7.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char devi... |
| CVE-2026-86792 | HIGH | 8.8 | 0.5% | Sep 16, 2026 | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connectio... |
| CVE-2026-86474 | HIGH | 7.7 | — | Sep 16, 2026 | The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions p... |
| CVE-2026-86466 | HIGH | 8.1 | 0.1% | Sep 16, 2026 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience c... |
| CVE-2026-85628 | HIGH | 7 | 0.1% | Sep 16, 2026 | Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application ... |
| CVE-2026-82310 | HIGH | 7.2 | 0.3% | Sep 16, 2026 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation... |
| CVE-2026-79993 | HIGH | 7.5 | 0.2% | Sep 16, 2026 | The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authent... |
| CVE-2026-73455 | HIGH | 7.5 | 0.5% | Sep 16, 2026 | On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafte... |
| CVE-2026-73435 | HIGH | 8.2 | 0.2% | Sep 16, 2026 | On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafte... |
| CVE-2026-59969 | HIGH | 7.5 | 0.1% | Sep 16, 2026 | Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, z... |
| CVE-2026-59739 | HIGH | 7.5 | 0.2% | Sep 16, 2026 | Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can dis... |
| CVE-2026-14917 | HIGH | 7.7 | — | Sep 16, 2026 | A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is ... |
| CVE-2026-89792 | HIGH | 7.1 | 0.1% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config ... |
| CVE-2026-89791 | HIGH | 7.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival r... |
| CVE-2026-89789 | HIGH | 7.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error p... |
| CVE-2026-89782 | HIGH | 8.4 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MA... |
| CVE-2026-89781 | HIGH | 8.4 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_bu... |
| CVE-2026-89777 | HIGH | 8.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on ... |
| CVE-2026-89774 | HIGH | 8.8 | 0.2% | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now