2026 CVE Vulnerabilities
43,896 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53088 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb ... |
| CVE-2026-53086 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmg... |
| CVE-2026-53055 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-fre... |
| CVE-2026-53049 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_l... |
| CVE-2026-53046 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qual... |
| CVE-2026-53045 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The cod... |
| CVE-2026-53043 | CRITICAL | 9.1 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regi... |
| CVE-2026-53010 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durab... |
| CVE-2026-53006 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching sad... |
| CVE-2026-53002 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace... |
| CVE-2026-52999 | CRITICAL | 9.1 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on... |
| CVE-2026-52993 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_ms... |
| CVE-2026-52989 | CRITICAL | 9.8 | 0.3% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() er... |
| CVE-2026-52986 | CRITICAL | 9.8 | 0.6% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strto... |
| CVE-2026-52982 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_st... |
| CVE-2026-52958 | CRITICAL | 9.1 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdm... |
| CVE-2026-52955 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crus... |
| CVE-2026-56121 | CRITICAL | 9.8 | 0.9% | Jun 24, 2026 | Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attacke... |
| CVE-2026-56111 | CRITICAL | 9.1 | 0.5% | Jun 24, 2026 | Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-... |
| CVE-2026-56351 | CRITICAL | 9.6 | 0.2% | Jun 24, 2026 | n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allow... |
| CVE-2026-56237 | CRITICAL | 9.3 | 0.3% | Jun 24, 2026 | Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are e... |
| CVE-2026-56223 | CRITICAL | 9.3 | 0.2% | Jun 24, 2026 | Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that all... |
| CVE-2026-52931 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender va... |
| CVE-2026-52924 | CRITICAL | 9.8 | 0.3% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling ... |
| CVE-2026-52914 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now