| Zammad GmbH Zammad Improper Privilege Management Vulnerability CVE-2026-102490 | Severity critical Exploited yes |
| Zammad GmbH Zammad Session Fixation Vulnerability CVE-2026-102489 | Severity critical Exploited yes |
| kernel: usb: typec: ucsi: unregister debugfs entries on teardown CVE-2026-100079 | Severity medium |
| In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mei: pass correct argument to function
The first… CVE-2026-100078 | Severity medium |
| kernel: drm/msm: Recover HW before retire hung submit CVE-2026-100077 | Severity medium |
| kernel: staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths CVE-2026-100076 | Severity medium |
| kernel: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters CVE-2026-100075 | Severity critical |
| In the Linux kernel, the following vulnerability has been resolved:
bpf: Mark bpf_refcount field as unique
BPF_REFCOUNT is not marked as… CVE-2026-100074 | Severity medium |
| kernel: KVM: x86/mmu: Check write tracking in all address spaces CVE-2026-98164 | Severity medium |
| kernel: cgroup: Avoid iteration of dying tasks with zero refcount CVE-2026-98163 | Severity high |
| kernel: smb/server: fix tree connection leak in smb2_tree_connect() CVE-2026-98162 | Severity medium |
| kernel: nvdimm: pmem: keep PREFLUSH before data writes CVE-2026-98161 | Severity medium |
| kernel: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() CVE-2026-98160 | Severity medium |
| kernel: nvmet-rdma: fix queue leak when connect backlog is exceeded CVE-2026-98152 | Severity medium |
| kernel: ksmbd: safely drain sessions during logoff CVE-2026-98115 | Severity high |
| kernel: Bluetooth: hci_core: Fix race condition during device registration CVE-2026-98109 | Severity medium |
| kernel: bpf: Mark signal tracepoint siginfo arguments as scalar CVE-2026-98062 | Severity medium |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in… CVE-2026-89276 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in… CVE-2026-89275 | Severity critical |
| Acronis Backup Incorrect Default Permissions Vulnerability CVE-2026-87886 | Exploited yes |
| IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An… CVE-2026-84842 | Severity high |
| IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated… CVE-2026-84440 | Severity high |
| IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged… CVE-2026-84436 | Severity critical |
| IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality… CVE-2026-84422 | Severity high |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in… CVE-2026-84412 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation… CVE-2026-83660 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A… CVE-2026-82443 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A… CVE-2026-82013 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')… CVE-2026-82011 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')… CVE-2026-82010 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')… CVE-2026-82009 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the… CVE-2026-82008 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the… CVE-2026-82003 | Severity high |
| Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the… CVE-2026-75728 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the… CVE-2026-75723 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in… CVE-2026-75721 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in… CVE-2026-75703 | Severity critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in… CVE-2026-75699 | Severity critical |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass… CVE-2026-75624 | Severity high |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in… CVE-2026-73369 | Severity critical |
| dotnet10.0: dotnet9.0: .NET Elevation of Privilege Vulnerability CVE-2026-69806 | Severity high |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful… CVE-2026-65130 | Severity critical |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A… CVE-2026-65129 | Severity high |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of… CVE-2026-65128 | Severity high |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information… CVE-2026-65127 | Severity medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral… CVE-2026-65126 | Severity high |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path… CVE-2026-65125 | Severity high |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of… CVE-2026-65124 | Severity high |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A… CVE-2026-65121 | Severity critical |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A… CVE-2026-65118 | Severity critical |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A… CVE-2026-65117 | Severity high |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A… CVE-2026-65115 | Severity medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical… CVE-2026-65114 | Severity critical |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A… CVE-2026-65113 | Severity critical |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A… CVE-2026-65112 | Severity medium |
| kernel: HID: multitouch: fix out-of-bounds bit access on mt_io_flags CVE-2026-64364 | Severity high |
| kernel: USB: serial: keyspan_pda: fix information leak CVE-2026-64336 | Severity medium |
| kernel: nvme: target: rdma: fix ndev refcount leak on queue connect CVE-2026-64321 | Severity medium |
| kernel: net/mlx5e: xsk: Fix unlocked writing to ICOSQ CVE-2026-64210 | Severity high |
| kernel: netfs: Fix netfs_read_folio() to wait on writeback CVE-2026-64058 | Severity high |
| kernel: ovpn: fix race between deleting interface and adding new peer CVE-2026-64043 | Severity medium |
| kernel: vfio/pci: Check BAR resources before exporting a DMABUF CVE-2026-64042 | Severity high |
| kernel: ASoC: codecs: fs210x: fix possible buffer overflow CVE-2026-64041 | Severity high |
| kernel: accel/rocket: fix UAF via dangling GEM handle in create_bo CVE-2026-64008 | Severity high |
| kernel: ALSA: pcm: oss: Fix setup list UAF on proc write error CVE-2026-64001 | Severity high |
| kernel: ethtool: cmis: require exact CDB reply length CVE-2026-63996 | Severity high |
| kernel: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() CVE-2026-63993 | Severity critical |
| kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp CVE-2026-63975 | Severity high |
| kernel: net: mana: Add NULL guards in teardown path to prevent panic on attach failure CVE-2026-63973 | Severity medium |
| kernel: net: mana: Skip redundant detach on already-detached port CVE-2026-63972 | Severity high |
| kernel: sctp: fix race between sctp_wait_for_connect and peeloff CVE-2026-63971 | Severity high |
| kernel: vsock/virtio: bind uarg before filling zerocopy skb CVE-2026-63970 | Severity high |
| kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role CVE-2026-53359 | Severity high |
| Linux Kernel Out-of-Bounds Write Vulnerability CVE-2026-53266 | Severity high Exploited yes |
| kernel: Linux kernel (xsk): Out-of-bounds memory access via TOCTOU race condition CVE-2026-53250 | Severity high |
| kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() CVE-2026-53196 | Severity medium |
| kernel: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction CVE-2026-53178 | Severity high |
| kernel: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN CVE-2026-53176 | Severity critical |
| kernel: wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() CVE-2026-53098 | Severity high |
| kernel: net: pull headers in qdisc_pkt_len_segs_init() CVE-2026-53091 | Severity high |
| kernel: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops CVE-2026-53078 | Severity high |
| kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp CVE-2026-53071 | Severity high |
| kernel: crypto: ccp - copy IV using skcipher ivsize CVE-2026-53016 | Severity high |
| kernel: ksmbd: fix use-after-free in smb2_open during durable reconnect CVE-2026-53010 | Severity critical |
| kernel: ipv6: fix possible UAF in icmpv6_rcv() CVE-2026-53006 | Severity critical |
| kernel: af_unix: Drop all SCM attributes for SOCKMAP CVE-2026-53005 | Severity high |
| kernel: netfilter: conntrack: remove sprintf usage CVE-2026-53002 | Severity critical |
| kernel: netfilter: nat: use kfree_rcu to release ops CVE-2026-53000 | Severity high |
| kernel: netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase CVE-2026-52988 | Severity high |
| kernel: drm/amdgpu: avoid double drm_exec_fini() in userq validate CVE-2026-52987 | Severity high |
| kernel: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size CVE-2026-52961 | Severity medium |
| kernel: ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE CVE-2026-52944 | Severity medium |
| kernel: sctp: purge outqueue on stale COOKIE-ECHO handling CVE-2026-52924 | Severity critical |
| kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry CVE-2026-46316 | Severity critical |
| kernel: staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc CVE-2026-46305 | Severity medium |
| kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF CVE-2026-46242 | Severity high |
| kernel: mptcp: pm: ADD_ADDR rtx: free sk if last CVE-2026-46170 | Severity medium |
| kernel: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount CVE-2026-46158 | Severity medium |
| kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() CVE-2026-46117 | Severity high |
| kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete CVE-2026-46116 | Severity high |