2026 CVE Vulnerabilities
66,169 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97539 | — | — | 0.2% | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: xusbatm: don't rely on id table pointer arithm... |
| CVE-2026-97538 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus_rog_ryujin) Validate HID report length... |
| CVE-2026-97537 | — | — | 0.2% | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix queue teardown NULL dma_free and... |
| CVE-2026-97536 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix use-after-free of qpair work on ... |
| CVE-2026-97535 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound VP index against VP_CTRL IOCB ... |
| CVE-2026-97534 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: accurately adjust free_sections during free_s... |
| CVE-2026-97533 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Acquire init_mm read lock on attribute ... |
| CVE-2026-97532 | — | — | 0.2% | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Null out freed pointers in qla2x00_m... |
| CVE-2026-97531 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Skip vport under deletion in report ... |
| CVE-2026-97530 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix soft lockup polling continuation... |
| CVE-2026-97529 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate BSG request_len before read... |
| CVE-2026-97528 | HIGH | 8.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Unlink NVMe unsol ctx before freeing... |
| CVE-2026-97527 | HIGH | 8.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize NVMe unsol ctx list with a... |
| CVE-2026-97526 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/pai: Support CPU hotplug for PMU PAI The comm... |
| CVE-2026-97525 | HIGH | 8.2 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Allocate split page tables as kernel pa... |
| CVE-2026-97524 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid unneeded actions on subflow reset Onc... |
| CVE-2026-97523 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: close race between scheduler and state chang... |
| CVE-2026-97522 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix bad accounting in __mptcp_subflow_push_p... |
| CVE-2026-97228 | LOW | 2.7 | — | Sep 25, 2026 | Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status com... |
| CVE-2026-27867 | MEDIUM | 4.8 | 0.4% | Sep 25, 2026 | An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration actio... |
| CVE-2026-97898 | HIGH | 8.4 | — | Sep 25, 2026 | Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unloc... |
| CVE-2026-92106 | LOW | 2.3 | — | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_htm... |
| CVE-2026-97863 | MEDIUM | 6.3 | 0.3% | Sep 25, 2026 | The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to ... |
| CVE-2026-92573 | MEDIUM | 6.5 | — | Sep 25, 2026 | Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message d... |
| CVE-2026-92564 | HIGH | 7.5 | 0.2% | Sep 25, 2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now