2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-89803HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the channel-kill event bef...
CVE-2026-89801HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix premature region free on fail...
CVE-2026-89799HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_get_stackid The get...
CVE-2026-89795HIGH8.4In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset...
CVE-2026-86585HIGH7.7The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01...
CVE-2026-14916HIGH7.7A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit...
CVE-2026-89793HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char devi...
CVE-2026-86792HIGH8.8Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connectio...
CVE-2026-86474HIGH7.7The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions p...
CVE-2026-86466HIGH8.1Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience c...
CVE-2026-85628HIGH7Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application ...
CVE-2026-82310HIGH7.2Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation...
CVE-2026-79993HIGH7.5The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authent...
CVE-2026-73455HIGH7.5On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafte...
CVE-2026-73435HIGH8.2On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafte...
CVE-2026-59969HIGH7.5Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, z...
CVE-2026-59739HIGH7.5Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can dis...
CVE-2026-14917HIGH7.7A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is ...
CVE-2026-89792HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config ...
CVE-2026-89791HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival r...
CVE-2026-89789HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error p...
CVE-2026-89782HIGH8.4In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MA...
CVE-2026-89781HIGH8.4In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_bu...
CVE-2026-89777HIGH8.8In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on ...
CVE-2026-89774HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now