boxscore/security
Saturday, July 25, 2026 · all times UTC← 2026-07-24 · archive · 2026-07-26 →

284 CVEs published July 25, 2026: 25 critical, 111 high, 21 medium, 0 low; 0 in KEV; 1 with a public exploit reference; 127 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 259 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published4239698813682563
KEV catalog size1670

133 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux634155220211069802730.27.8.0016+400
microsoft65313561049273008378322.47.8.0039+434
red hat761759857110400.07.1.0028+34
apple3801195219378.86.5.0036+3
google26356241173514.38.8.0030+23
canonical330210000.07.8.0013+3
android010100161100.08.4.0171-1
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco7194610961263.28.6.2459+4
fortinet1017248028529.46.3.0051+9
palo alto networks1015017514213.34.7.0028+7
vmware7716002100.08.7.0044+7
f51540007120.09.2.04020
ivanti051000335100.010.0.8152-1
checkpoint3431003250.09.2.4696+2
broadcom2400204250.05.1.0877+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
mozilla67724226401300.09.1.0031+67
apache275914331204011.77.5.0058+12
docker030120100.05.7.0015-3
wordpress22101052100.07.9.8435+2
gitlab02000042100.0.44510
github110010000.04.7.0017+1
kubernetes110001000.02.4.0024+1
drupal01100051100.09.8.88320
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091113212539304574030.37.6.0031+1107
ibm32401611130700.08.4.0028+31
adobe16279104075414.88.6.0144+9
solarwinds15191511011421.19.1.0044+14
progress181831050900.07.8.0031+18
atlassian3303001300.08.0.0026+3
zohocorp331110000.07.1.0048+3
veeam110100400.08.4.0013+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link78006126112.55.5.0073+7
hikvision5603202116.77.2.0024+5
bosch220200000.08.0.0018+2
rockwell automation111000000.09.2.0030+1
siemens010100100.08.7.00320
dahua000000200
qnap000000800
schneider electric000000100
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb5757326253000.07.1.0025+57
grafana841214223000.06.5.0033+2
open ises037214210000.06.9.00210
netty103262411000.07.5.0051-4
regularlabs.com292961490000.07.5.0022+29
watchguard172811890400.07.3.0026+17
nlnet labs242704176000.05.9.0024+24
mongodb262611771200.07.1.0023+26

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1109
microsoft653
linux641
red hat89
mozilla67
surrealdb57
apple40
ibm39
regularlabs.com29
apache28
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco12
apple7
fortinet5
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven16
crates.io1
npm1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-25089Fortinet0
CVE-2026-39808Fortinet0
CVE-2026-45659Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171711
CVE-2021-27102Accellion2021-11-171711
CVE-2021-27101Accellion2021-11-171711
CVE-2021-27103Accellion2021-11-171711
CVE-2021-21017Adobe2021-11-171711
CVE-2021-28550Adobe2021-11-171711
CVE-2021-42013Apache2021-11-171711
CVE-2021-41773Apache2021-11-171711
CVE-2021-30858Apple2021-11-171711
CVE-2021-30860Apple2021-11-171711

Transactions

EXPLOIT PUBLISHEDCVE-2026-10681 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65693 (microweber). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65711 (nuxsmin sysPass). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66004 (ahujasid blender-mcp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66005 (janhq jan). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66027 (kortix-ai suna). Public exploit reference added.

DUE DATE PASSEDCVE-2021-27137 (DD-WRT). CISA remediation deadline was July 24, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-0770 (Langflow). CISA remediation deadline was July 24, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-63030 (WordPress). CISA remediation deadline was July 24, 2026; still in catalog.

Yesterday's Results

284 CVEs published. 25 box scores, 259 table rows — nothing truncated.

RRWO Catalyst::View::Wkhtmltopdf — Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0130   68.1     —
AFFECTED
  Product                      Versions     Fixed
  Catalyst::View::Wkhtmltopdf  unspecified  —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 25  Published (CNA: CPANSec)
CWE-78 · CNA: CPANSec · 5 references · NVD status: Deferred
Linux Linux — nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0073   51.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    a07b4970f464f13640e28e16dad6cfa33647cc99 –  —
  Linux    4.8 –                                       6.12.96
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 4 references · NVD status: Awaiting Analysis
Linux Linux — RDMA/siw: bound Read Response placement to the RREAD length
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   50.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    8b6a361b8c482f22ac99c3273285ff16b23fba91 –  —
  Linux    5.3 –                                       5.10.261
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CWE-787 · CNA: Linux · 8 references · NVD status: Analyzed
Linux Linux — RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0068   49.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    9cb837480424e78ed585376f944088246685aec3 –  —
  Linux    5.8 –                                       5.15.212
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 7 references · NVD status: Analyzed
Linux Linux — spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    09c04466ce7ea494993c0635ba5edb6d2222a806 –  —
  Linux    5.2 –                                       5.10.261
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — smb: client: reject overlapping data areas in SMB2 responses
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0067   49.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    31c6312608c60b72a1feb99a5afb680645a3e8a3 –  —
  Linux    unspecified                                 —
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Analyzed
Linux Linux — tipc: fix out-of-bounds read in broadcast Gap ACK blocks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0054   42.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    d7626b5acff9227e2a65da636a53e09bdafdc0aa –  —
  Linux    5.8 –                                       5.10.261
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Themehigh Checkout Field Editor for WooCommerce (Pro) — Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0053   42.2     —
AFFECTED
  Product                                      Versions     Fixed
  Checkout Field Editor for WooCommerce (Pro)  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 25  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 2 references · NVD status: Deferred
Linux Linux — nvmet-auth: validate reply message payload bounds against transfer length
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0052   42.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    db1312dd95488b5e6ff362ff66fcf953a46b1821 –  —
  Linux    6.0 –                                       6.6.145
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 5 references · NVD status: Awaiting Analysis
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0050   40.7     —
AFFECTED
  Product  Versions     Fixed
  Redis    unspecified  —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 25  Published (CNA: mitre)
CWE-415 · CNA: mitre · 6 references · NVD status: Received
Linux Linux — bpf: Reject fragmented frames in devmap
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0050   40.7     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    e624d4ed4aa8cc3c69d1359b0aaea539203ed266 –  —
  Linux    5.14 –                                      5.15.212
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 7 references · NVD status: Awaiting Analysis
Linux Linux — crypto: pcrypt - restore callback for non-parallel fallback
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0050   40.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    a92ccd3618e42333ac6f150ecdac14dca298bc7a –  —
  Linux    6.13 –                                      5.10.261
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0050   40.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    b6366f048e0caff28af5335b7af2031266e1b06b –  —
  Linux    4.1 –                                       5.10.261
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0049   40.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    eb817368f50c1cbe1bd07044124aad7db6330e3a –  —
  Linux    5.15 –                                      6.1.178
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Awaiting Analysis
Linux Linux — NTB: epf: Avoid calling pci_irq_vector() from hardirq context
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0049   40.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    812ce2f8d14ea791edd88c36ebcc9017bf4c88cb –  —
  Linux    5.12 –                                      5.15.212
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 7 references · NVD status: Awaiting Analysis
Linux Linux — ksmbd: run set info with opener credentials
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0048   39.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 –  —
  Linux    5.15 –                                      6.1.178
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Awaiting Analysis
Linux Linux — ksmbd: serialize QUERY_DIRECTORY requests per file
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0048   39.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 –  —
  Linux    5.15 –                                      6.1.178
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Awaiting Analysis
Linux Linux — tcp: restore RCU grace period in tcp_ao_destroy_sock
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0047   39.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    51e547e8c89c661f6fbede4a28b1d33b13625683 –  —
  Linux    6.18 –                                      6.18.39
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 3 references · NVD status: Received
Linux Linux — ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0047   38.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 –  —
  Linux    5.15 –                                      6.1.178
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Awaiting Analysis
Linux Linux — ksmbd: use opener credentials for delete-on-close
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0047   38.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f44158485826c076335d6860d35872271a83791d –  —
  Linux    5.15 –                                      6.6.145
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 5 references · NVD status: Awaiting Analysis
Linux Linux — svcrdma: wake sq waiters when the transport closes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0047   38.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    ccc89b9d1ed233349cfe8d87b842e7351b74d8de –  —
  Linux    7.1 –                                       7.1.4
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 2 references · NVD status: Analyzed
Linux Linux — ksmbd: track the connection owning a byte-range lock
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0047   38.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f5a544e3bab78142207e0242d22442db85ba1eff –  —
  Linux    5.15 –                                      5.15.212
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 7 references · NVD status: Awaiting Analysis
Linux Linux — ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0046   38.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 –  —
  Linux    5.15 –                                      6.1.178
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Awaiting Analysis
Linux Linux — smb: client: restrict implied bcc[0] exemption to responses without data area
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  H    8.2   .0046   38.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    093b2bdad3221e3fae3c26d89387e7297a157664 –  —
  Linux    3.6 –                                       5.10.261
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — smb: client: fix double-free in SMB2_flush() replay
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0046   37.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    433042a91f9373241307725b52de573933ffedbf –  —
  Linux    6.8 –                                       6.6.145
TIMELINE
  Jul 19  Reserved by CNA
  Jul 25  Published (CNA: Linux)
CNA: Linux · 5 references · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-643849.837.9LinuxLinuxsmb: client: fix change notify replay double-free
CVE-2026-643859.837.9LinuxLinuxsmb: client: fix double-free in SMB2_ioctl() replay
CVE-2026-643869.837.9LinuxLinuxsmb: client: fix query_info() replay double-free
CVE-2026-643879.837.9LinuxLinuxsmb: client: fix query directory replay double-free
CVE-2026-643919.837.9LinuxLinuxksmbd: use opener credentials for ADS I/O
CVE-2026-643898.237.6LinuxLinuxksmbd: validate NTLMv2 response before updating session key
CVE-2026-643808.236.9LinuxLinuxsmb: client: harden POSIX SID length parsing
CVE-2026-644147.536.7LinuxLinuxnetfilter: handle unreadable frags
CVE-2026-6601210.036.4siyuan-notesiyuanCWE-862SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP
CVE-2026-643968.836.2LinuxLinuxksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
CVE-2026-644378.836.2LinuxLinuxksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
CVE-2026-644399.835.8LinuxLinuxcrypto: krb5 - filter out async aead implementations at alloc
CVE-2026-644358.235.4LinuxLinuxaudit: Fix data races of skb_queue_len() readers on audit_queue
CVE-2026-108188.135.0WPFormsWPForms ProCWE-434WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Up…
CVE-2026-643688.134.8LinuxLinuxmm/slab: do not limit zeroing to orig_size when only red zoning is enabled
CVE-2026-643957.533.8LinuxLinuxksmbd: require source read access for duplicate extents
CVE-2026-663748.132.1nicKnot ResolverCWE-1284Knot Resolver before 6.4.1 allows remote code execution via a heap-based buff…
CVE-2026-660139.332.0openremoteopenremoteCWE-639OpenRemote before 1.26.2 Authentication Bypass via Console Registration
CVE-2026-644109.831.1LinuxLinuxnetfilter: flowtable: IPIP tunnel hardware offload is not yet support
CVE-2026-645239.829.0LinuxLinuxnet/handshake: Take a long-lived file reference at submit
CVE-2026-644008.628.8LinuxLinuxksmbd: prevent path traversal bypass by restricting caseless retry
CVE-2026-643828.828.5LinuxLinuxsmb: client: fix double-free in SMB2_open() replay
CVE-2026-645228.827.8LinuxLinuxnet/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA
CVE-2026-643138.827.5LinuxLinuxcrypto: ecc - Fix carry overflow in vli multiplication
CVE-2026-643648.827.5LinuxLinuxHID: multitouch: fix out-of-bounds bit access on mt_io_flags
CVE-2026-644458.824.4LinuxLinuxstaging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
CVE-2026-643797.123.5LinuxLinuxsmb: client: mask server-provided mode to 07777 in modefromsid
CVE-2026-644428.121.1LinuxLinuxstaging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cm…
CVE-2026-644438.120.4LinuxLinuxstaging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
CVE-2026-644448.120.4LinuxLinuxstaging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
CVE-2026-644068.019.8LinuxLinuxBluetooth: fix UAF in bt_accept_dequeue()
CVE-2026-644408.118.6LinuxLinuxstaging: rtl8723bs: fix OOB write in HT_caps_handler()
CVE-2026-644037.118.5LinuxLinuxBluetooth: L2CAP: validate option length before reading conf opt value
CVE-2026-644088.818.1LinuxLinuxBluetooth: bnep: pin L2CAP connection during netdev registration
CVE-2026-644418.817.4LinuxLinuxstaging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and…
CVE-2026-643668.817.0LinuxLinuxHID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
CVE-2026-644348.816.2LinuxLinuxBluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
CVE-2026-645158.315.0LinuxLinuxwifi: mac80211: fix MLE defragmentation
CVE-2026-64505await12.7LinuxLinuxusb: gadget: function: rndis: add length check for header
CVE-2026-644527.112.6LinuxLinux6lowpan: fix NHC entry use-after-free on error path
CVE-2026-64307await12.2LinuxLinuxcrypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)
CVE-2026-64308await12.2LinuxLinuxcrypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)
CVE-2026-64309await12.2LinuxLinuxcrypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
CVE-2026-64310await12.2LinuxLinuxcrypto: ccp - Do not initialize SNP for SEV ioctls
CVE-2026-64306await11.6LinuxLinuxcrypto: drbg - Fix returning success on failure in CTR_DRBG
CVE-2026-64337await11.6LinuxLinuxusb: mtu3: unmap request DMA on queue failure
CVE-2026-64363await11.6LinuxLinuxHID: appleir: fix UAF on pending key_up_timer in remove()
CVE-2026-64301await10.9LinuxLinuxregulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
CVE-2026-64346await10.9LinuxLinuxusb: gadget: udc: Fix use-after-free in gadget_match_driver
CVE-2026-154256.410.3yoastYoast SEO – Advanced SEO with real-time guidance and built-in AICWE-79Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via P…
CVE-2026-64326await10.2LinuxLinuxblock: skip sync_blockdev() on surprise removal in bdev_mark_dead()
CVE-2026-64327await10.2LinuxLinuxusb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks
CVE-2026-64328await10.2LinuxLinuxusb: gadget: f_fs: Fix DMA fence leak
CVE-2026-64302await9.9LinuxLinuxx86/mm: Fix freeing of PMD-sized vmemmap pages
CVE-2026-64314await9.9LinuxLinuxcrypto: chacha20poly1305 - validate poly1305 template argument
CVE-2026-64339await9.9LinuxLinuxusb: misc: usbio: bound bulk IN response length to the received transfer
CVE-2026-64446await9.5LinuxLinuxstaging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
CVE-2026-64495await9.6LinuxLinuxiio: gyro: bmg160: bail out when bandwidth/filter is not in table
CVE-2026-64325await8.9LinuxLinuxwifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon
CVE-2026-64351await8.4LinuxLinuxnet: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
CVE-2026-64484await8.4LinuxLinuxALSA: es1938: check snd_ctl_new1() return value
CVE-2026-64455await8.3LinuxLinuxUSB: chaoskey: Fix slab-use-after-free in chaoskey_release()
CVE-2026-64461await8.3LinuxLinuxPCI: mediatek: Fix IRQ domain leak when port fails to enable
CVE-2026-64462await8.3LinuxLinuxPCI: altera: Fix resource leaks on probe failure
CVE-2026-64465await8.3LinuxLinuxusb: xhci: Fix sleep in atomic context in xhci_free_streams()
CVE-2026-64470await8.3LinuxLinuxBluetooth: btusb: fix use-after-free on marvell probe failure
CVE-2026-64471await8.3LinuxLinuxBluetooth: btusb: fix use-after-free on registration failure
CVE-2026-64478await8.3LinuxLinuxALSA: usb-audio: avoid kobject path lookup in DualSense match
CVE-2026-64483await8.3LinuxLinuxALSA: firewire: isight: bound the sample count to the packet payload
CVE-2026-64487await8.3LinuxLinuxALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
CVE-2026-64488await8.3LinuxLinuxALSA: aoa: check snd_ctl_new1() return value
CVE-2026-64369await7.9LinuxLinuxs390: Revert support for DCACHE_WORD_ACCESS
CVE-2026-64472await7.9LinuxLinuxvfio/mlx5: Fix racy bitfields and tighten struct layout
CVE-2026-64479await7.9LinuxLinuxALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
CVE-2026-64480await7.9LinuxLinuxALSA: ice1712: check snd_ctl_new1() return value
CVE-2026-64482await7.9LinuxLinuxALSA: gus: check snd_ctl_new1() return value
CVE-2026-64454await7.9LinuxLinuxusb: dwc3: run gadget disconnect from sleepable suspend context
CVE-2026-64458await7.9LinuxLinuxmm/damon/ops-common: handle extreme intervals in damon_hot_score()
CVE-2026-64476await7.9LinuxLinuxvfio/pci: Latch disable_idle_d3 per device
CVE-2026-64486await7.9LinuxLinuxALSA: cmipci: check snd_ctl_new1() return value
CVE-2026-64489await7.9LinuxLinuxALSA: ymfpci: check snd_ctl_new1() return value
CVE-2026-64356await7.7LinuxLinuxxfs: fix memory leak in xfs_dqinode_metadir_create()
CVE-2026-64316await7.5LinuxLinuxcrypto: caam - use print_hex_dump_devel to guard key hex dumps
CVE-2026-64329await7.5LinuxLinuxusb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
CVE-2026-64330await7.5LinuxLinuxusb: typec: tcpm: Validate SVID index in svdm_consume_modes()
CVE-2026-64331await7.5LinuxLinuxusbip: vudc: fix NULL deref in vep_dequeue()
CVE-2026-64332await7.5LinuxLinuxUSB: ulpi: fix memory leak on registration failure
CVE-2026-64334await7.5LinuxLinuxUSB: serial: digi_acceleport: fix hard lockup on disconnect
CVE-2026-64335await7.5LinuxLinuxUSB: serial: digi_acceleport: fix broken rx after throttle
CVE-2026-64338await7.5LinuxLinuxUSB: misc: uss720: unregister parport on probe failure
CVE-2026-64340await7.5LinuxLinuxUSB: legousbtower: fix use-after-free on disconnect race
CVE-2026-64342await7.5LinuxLinuxUSB: iowarrior: fix use-after-free on disconnect
CVE-2026-64343await7.5LinuxLinuxUSB: ldusb: fix use-after-free on disconnect race
CVE-2026-64344await7.5LinuxLinuxUSB: idmouse: fix use-after-free on disconnect race
CVE-2026-64347await7.5LinuxLinuxusb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
CVE-2026-64359await7.5LinuxLinuxnilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
CVE-2026-64360await7.5LinuxLinuxhfs/hfsplus: zero-initialize buffer in hfs_bnode_read
CVE-2026-64362await7.5LinuxLinuxHID: lg-g15: cancel pending work on remove to fix a use-after-free
CVE-2026-64370await7.5LinuxLinuxposix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
CVE-2026-64371await7.5LinuxLinuxproc: protect ptrace_may_access() with exec_update_lock (part 1)
CVE-2026-64373await7.5LinuxLinuxcpufreq: Fix hotplug-suspend race during reboot
CVE-2026-64381await7.5LinuxLinuxsmb: client: Fix next buffer leak in receive_encrypted_standard()
CVE-2026-64425await7.5LinuxLinuxio_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
CVE-2026-64429await7.5LinuxLinuxgpio: eic-sprd: use raw_spinlock_t in the irq startup path
CVE-2026-64494await7.5LinuxLinuxiio: light: gp2ap002: fix runtime PM leak on read error
CVE-2026-64497await7.6LinuxLinuxiio: chemical: scd30: Cleanup initializations and fix sign-extension bug
CVE-2026-64503await7.5LinuxLinuxiio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
CVE-2026-64514await7.6LinuxLinuxuserfaultfd: gate must_wait writability check on pte_present()
CVE-2026-64474await7.4LinuxLinuxvfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
CVE-2026-64477await7.4LinuxLinuxx86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC ena…
CVE-2026-64457await7.3LinuxLinuxvirtio_pci: fix vq info pointer lookup via wrong index
CVE-2026-64473await7.3LinuxLinuxvfio: Remove device debugfs before releasing devres
CVE-2026-64491await7.1LinuxLinuxALSA: usx2y: us144mkii: fix work UAF on disconnect
CVE-2026-64336await7.0LinuxLinuxUSB: serial: keyspan_pda: fix information leak
CVE-2026-64345await7.0LinuxLinuxusb: gadget: f_printer: take kref only for successful open
CVE-2026-64348await7.0LinuxLinuxusb: free iso schedules on failed submit
CVE-2026-64350await7.0LinuxLinuxusb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
CVE-2026-64352await7.0LinuxLinuxbpf: Allow LPM map access from sleepable BPF programs
CVE-2026-64365await7.0LinuxLinuxHID: letsketch: fix UAF on inrange_timer at driver unbind
CVE-2026-64376await7.0LinuxLinuxfirmware_loader: fix device reference leak in firmware_upload_register()
CVE-2026-64405await7.0LinuxLinuxBluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
CVE-2026-64409await7.0LinuxLinuxBluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
CVE-2026-64417await7.0LinuxLinuxmm: shrinker: fix NULL pointer dereference in debugfs
CVE-2026-64419await7.0LinuxLinuxmm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
CVE-2026-64428await7.0LinuxLinuxgpio: sch: use raw_spinlock_t in the irq startup path
CVE-2026-64453await7.1LinuxLinuxusb: misc: usbio: fix disconnect UAF in client teardown
CVE-2026-64464await7.1LinuxLinuxxhci: sideband: fix ring sg table pages leak
CVE-2026-64466await7.1LinuxLinuxrust_binder: clear freeze listener on node removal
CVE-2026-64492await7.1LinuxLinuxiio: temperature: tmp006: use devm_iio_trigger_register
CVE-2026-64512await7.0LinuxLinuxACPI: CPPC: Suppress UBSAN warning caused by field misuse
CVE-2026-64513await6.8LinuxLinuxKVM: x86: Unconditionally recompute CR8 intercept on PPR update
CVE-2026-642868.26.8LinuxLinuxKVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
CVE-2026-642878.26.8LinuxLinuxKVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
CVE-2026-64305await6.5LinuxLinuxcrypto: qat - protect service table iterations with service_lock
CVE-2026-64321await6.5LinuxLinuxnvme: target: rdma: fix ndev refcount leak on queue connect
CVE-2026-64357await6.5LinuxLinuxxfs: fix exchmaps reservation limit check
CVE-2026-64358await6.5LinuxLinuxmedia: mtk-jpeg: cancel workqueue on release for supported platforms only
CVE-2026-64377await6.5LinuxLinuxcpufreq: qcom-cpufreq-hw: Fix possible double free
CVE-2026-64404await6.5LinuxLinuxBluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
CVE-2026-64407await6.5LinuxLinuxBluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()
CVE-2026-64415await6.5LinuxLinuxmm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup
CVE-2026-64416await6.5LinuxLinuxmm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host
CVE-2026-64421await6.5LinuxLinuxmedia: nxp: imx8-isi: Fix use-after-free on remove
CVE-2026-64424await6.5LinuxLinuxnetpoll: fix a use-after-free on shutdown path
CVE-2026-64427await6.5LinuxLinuxHID: logitech-dj: Fix maxfield check in DJ short report validation
CVE-2026-64433await6.5LinuxLinuxBluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
CVE-2026-64493await6.5LinuxLinuxiio: pressure: mpl115: fix runtime PM leak on read error
CVE-2026-64517await6.6LinuxLinuxdrm/xe/gsc: Fix double-free of managed BO in error path
CVE-2026-64518await6.5LinuxLinuxtcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().
CVE-2026-64519await6.6LinuxLinuxNFSD: Fix infinite loop in layout state revocation
CVE-2026-64528await6.5LinuxLinuxtty: serial: samsung: Remove redundant port lock acquisition in rx helpers
CVE-2026-64341await6.3LinuxLinuxUSB: iowarrior: fix use-after-free on disconnect race
CVE-2026-64349await6.3LinuxLinuxusb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
CVE-2026-64353await6.3LinuxLinuxbpf: Keep dynamic inner array lookups nullable
CVE-2026-64426await6.3LinuxLinuxio_uring/nop: fix file reference leak with IOSQE_FIXED_FILE
CVE-2026-64521await6.3LinuxLinuxpinctrl: meson: amlogic-a4: fix deadlock issue
CVE-2026-64500await6.2LinuxLinuxiio: adc: lpc32xx: Initialize completion before requesting IRQ
CVE-2026-64504await6.2LinuxLinuxiio: accel: bmc150: clamp the device-reported FIFO frame count
CVE-2026-642717.86.1LinuxLinuxCWE-129Input: touchwin - reset the packet index on every complete packet
CVE-2026-642737.86.1LinuxLinuxCWE-129Input: iforce - bound the device-reported force-feedback effect index
CVE-2026-642747.86.1LinuxLinuxCWE-787Input: goodix - clamp the device-reported contact count
CVE-2026-642767.86.1LinuxLinuxCWE-787Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
CVE-2026-642777.86.1LinuxLinuxCWE-125Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
CVE-2026-642967.86.1LinuxLinuxexfat: bound uniname advance in exfat_find_dir_entry()
CVE-2026-643047.86.1LinuxLinuxcrypto: qat - validate RSA CRT component lengths
CVE-2026-643227.86.1LinuxLinuxudf: validate sparing table length as an entry count, not a byte count
CVE-2026-643337.86.1LinuxLinuxUSB: serial: digi_acceleport: fix write buffer corruption
CVE-2026-642808.86.0LinuxLinuxfpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
CVE-2026-642707.86.0LinuxLinuxCWE-787Input: mms114 - reject an oversized device packet size
CVE-2026-642727.86.0LinuxLinuxCWE-129Input: mms114 - fix touch indexing for MMS134S and MMS136
CVE-2026-642937.85.8LinuxLinuxiommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read
CVE-2026-643007.85.8LinuxLinuxperf/aux: Fix page UAF in map_range()
CVE-2026-64451await5.9LinuxLinuxtracing: Fix NULL pointer dereference in func_set_flag()
CVE-2026-64506await5.8LinuxLinuxwifi: rtw89: correct drop logic for malformed AMPDU frames
CVE-2026-64527await5.7LinuxLinuxdrm/hyperv: validate VMBus packet size in receive callback
CVE-2026-642667.85.6LinuxLinuxCWE-416fuse: re-lock request before returning from fuse_ref_folio()
CVE-2026-642987.15.7LinuxLinuxNFSv4: include MAY_WRITE in open permission mask for O_TRUNC
CVE-2026-642997.15.6LinuxLinuxtracing: Prevent out-of-bounds read in glob matching
CVE-2026-643177.15.6LinuxLinuxisofs: bound Rock Ridge symlink components to the SL record
CVE-2026-643187.15.6LinuxLinuxpartitions: aix: bound the pp_count scan to the ppe array
CVE-2026-643237.15.6LinuxLinuxudf: validate VAT header length against the VAT inode size
CVE-2026-642657.85.6LinuxLinuxCWE-416fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
CVE-2026-642955.55.4LinuxLinuxCWE-476mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN ac…
CVE-2026-642597.85.4LinuxLinuxCWE-416fuse-uring: make a fuse_req on SQE commit only findable after memcpy
CVE-2026-642617.85.4LinuxLinuxCWE-416fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues
CVE-2026-643117.85.4LinuxLinuxcrypto: loongson - Remove broken and unused loongson-rng
CVE-2026-64499await5.4LinuxLinuxiio: adc: ti-ads1119: fix PM reference leak in buffer preenable
CVE-2026-64507await5.4LinuxLinuxx86/bugs: Enable IBPB flush on BPF JIT allocation
CVE-2026-64508await5.4LinuxLinuxbpf: Support for hardening against JIT spraying
CVE-2026-64509await5.4LinuxLinuxrust: block: fix GenDisk cleanup paths
CVE-2026-643247.85.3LinuxLinuxudf: validate free block extents against the partition length
CVE-2026-642755.55.2LinuxLinuxCWE-369Input: elan_i2c - prevent division by zero and arithmetic underflow
CVE-2026-642975.55.2LinuxLinuxCWE-476module: decompress: check return value of module_extend_max_pages()
CVE-2026-64511await5.3LinuxLinuxACPI: NFIT: core: Fix possible NULL pointer dereference
CVE-2026-64525await5.3LinuxLinuxxfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
CVE-2026-642565.55.2LinuxLinuxxfs: don't wrap around quota ids in dqiterate
CVE-2026-642895.55.2LinuxLinuxiommufd: Set upper bounds on cache invalidation entry_num and entry_len
CVE-2026-642905.55.2LinuxLinuxCWE-835iommufd: Break the loop on failure in iommufd_fault_fops_read()
CVE-2026-642945.55.2LinuxLinuxmm: do file ownership checks with the proper mount idmap
CVE-2026-64498await5.2LinuxLinuxiio: buffer: hw-consumer: free scan_mask on buffer release
CVE-2026-64526await5.1LinuxLinuxethtool: tsconfig: fix missing ethnl_ops_complete()
CVE-2026-644908.44.9LinuxLinuxALSA: virtio: Validate control metadata from the device
CVE-2026-642585.55.0LinuxLinuxCWE-476fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref
CVE-2026-642625.55.0LinuxLinuxfuse-uring: end fuse_req on io-uring cancel task work
CVE-2026-642635.55.0LinuxLinuxfuse-uring: fix moving cancelled entry to ent_in_userspace list
CVE-2026-642645.55.0LinuxLinuxfuse-uring: fix EFAULT clobber in fuse_uring_commit
CVE-2026-642675.55.0LinuxLinuxfuse: avoid 32-bit prune notification count wrap
CVE-2026-642785.55.0LinuxLinuxi2c: imx-lpi2c: mark I2C adapter when hardware is powered down
CVE-2026-642885.55.0LinuxLinuxCWE-476KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB
CVE-2026-642915.55.0LinuxLinuxiommufd: Set veventq_depth upper bound
CVE-2026-642925.55.0LinuxLinuxCWE-401iommufd: Move vevent memory allocation outside spinlock
CVE-2026-644567.74.5LinuxLinuxhwrng: virtio: clamp device-reported used.len at copy_data()
CVE-2026-643157.04.3LinuxLinuxcrypto: caam - use print_hex_dump_devel to guard key hex dumps
CVE-2026-645247.74.2LinuxLinuxdrm/hyperv: validate resolution_count and fix WIN8 fallback
CVE-2026-643677.84.0LinuxLinuxHID: hid-goodix-spi: validate report size to prevent stack buffer overflow
CVE-2026-644758.83.7LinuxLinuxvfio/pci: Release the VGA arbiter client on register_device() failure
CVE-2026-644497.83.7LinuxLinuxstaging: vme_user: bound slave read/write to the kern_buf size
CVE-2026-644637.83.7LinuxLinuxusb: typec: tcpci_rt1711h: unregister TCPCI port with devres
CVE-2026-644817.83.7LinuxLinuxALSA: hda/cs35l41: Fix firmware load work teardown
CVE-2026-642837.03.7LinuxLinuxCWE-190KVM: guest_memfd: Treat memslot binding offset+size as unsigned values
CVE-2026-644678.83.6LinuxLinuxrust_binder: use a u64 stride when cleaning up the offsets array
CVE-2026-644857.83.6LinuxLinuxALSA: compress: Fix task creation error unwind
CVE-2026-642855.53.6LinuxLinuxKVM: SEV: Pin source page for write when adding CPUID data for SNP guest
CVE-2026-644388.83.4LinuxLinuxcrypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
CVE-2026-644327.83.4LinuxLinuxfs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
CVE-2026-644687.83.4LinuxLinuxbinder: fix UAF in binder_free_transaction()
CVE-2026-644697.83.4LinuxLinuxbinder: fix UAF in binder_thread_release()
CVE-2026-645297.83.4LinuxLinuxcrypto: qat - remove unused character device and IOCTLs
CVE-2026-644477.83.3LinuxLinuxstaging: media: ipu7: fix double-free and use-after-free in error paths
CVE-2026-644227.13.2LinuxLinuxnet: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
CVE-2026-645208.43.1LinuxLinuxfirmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies
CVE-2026-643547.82.9LinuxLinuxbpf: Validate BTF repeated field counts before expansion
CVE-2026-643617.83.0LinuxLinuxhfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
CVE-2026-643757.83.0LinuxLinuxproc: protect ptrace_may_access() with exec_update_lock (FD links)
CVE-2026-643787.83.0LinuxLinuxwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
CVE-2026-644027.82.9LinuxLinuxcoresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
CVE-2026-642797.82.8LinuxLinuxCWE-362i2c: core: fix adapter deregistration race
CVE-2026-643727.82.7LinuxLinuxcpufreq: pcc: fix use-after-free and double free in _OSC evaluation
CVE-2026-644017.82.7LinuxLinuxsmb: client: resolve SWN tcon from live registrations
CVE-2026-644237.82.7LinuxLinuxipv4: igmp: remove multicast group from hash table on device destruction
CVE-2026-644117.12.7LinuxLinuxnetfilter: ebtables: terminate table name before find_table_lock()
CVE-2026-644127.12.7LinuxLinuxnetfilter: ebtables: module names must be null-terminated
CVE-2026-644967.12.7LinuxLinuxiio: event: Fix event FIFO reset race
CVE-2026-642607.82.6LinuxLinuxCWE-362fuse-uring: Avoid queue->stopped races and set/read that value under lock
CVE-2026-644187.82.6LinuxLinuxmm: shrinker: fix shrinker_info teardown race with expansion
CVE-2026-644317.82.5LinuxLinuxntfs: avoid calling post_write_mst_fixup() for invalid index_block
CVE-2026-642847.12.5LinuxLinuxCWE-367KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits
CVE-2026-644137.02.3LinuxLinuxnetfilter: ebtables: zero chainstack array
CVE-2026-643887.82.2LinuxLinuxsmb/client: fix chown/chgrp with SMB3 POSIX Extensions
CVE-2026-645027.82.1LinuxLinuxiio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices
CVE-2026-644367.12.1LinuxLinuxnet: af_key: initialize alg_key_len for IPComp states
CVE-2026-644207.02.0LinuxLinuxmfd: cros_ec: Delay dev_set_drvdata() until probe success
CVE-2026-644607.02.0LinuxLinuxPCI/IOV: Skip VF Resizable BAR restore on read error
CVE-2026-645017.11.8LinuxLinuxiio: adc: ad_sigma_delta: fix CS held asserted and state leaks
CVE-2026-645168.81.6LinuxLinuxdrm/amdgpu/vce1: Fix VCE 1 firmware size and offsets
CVE-2026-645107.01.5LinuxLinuxACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
CVE-2026-642824.71.2LinuxLinuxCWE-362KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier
CVE-2026-660114.80.6ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options
CVE-2026-106817.00.4zephyrprojectzephyrCWE-362SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-25 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.