CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Vulnerabilities

September 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 2 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 5,936 vulnerabilities across 17,974 returned patch records from 5 vendors. Filter the month to date, or browse the static page trail without JavaScript.

17,974all patch recordsClear filters1,064criticalShow these records2Microsoft exploitation detectedShow these records4Microsoft in the Known Exploited Vulnerabilities catalogShow these records14,542tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 78 of 90 · records 15,401 to 15,600 of 17,974

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-93804 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: ibss: wait for in-flight TX on disconnect
CVE-2026-97423 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecxl/region: Validate partition index before array access
CVE-2026-93247 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference
CVE-2026-97475 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablethermal/drivers/tegra/soctherma: Switch to devm cooling device registration
CVE-2026-93256 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablearm64: hibernate: mask DAIF before restoring hibernated kernel
CVE-2026-93251 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableACPI: bus: Introduce acpi_bus_get_primary_device()
CVE-2026-93226 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv6: use RCU iterator to dump route exceptions
CVE-2026-93821 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePCI: altera: Protect root bus removal with rescan lock
CVE-2026-93271 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate
CVE-2026-97515 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845
CVE-2026-93279 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablestaging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown
CVE-2026-97480 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletty: serial: 8250: protect against NULL uart->port.dev in register
CVE-2026-93214 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
CVE-2026-93259 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepowerpc/irq: Fix missing r2 clobber in PCREL inline assembly
CVE-2026-93261 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelocking/lockdep: Fix NULL pointer dereference in __lock_set_class()
CVE-2026-97435 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: dsa: sja1105: flower: reject cross-chip redirect
CVE-2026-97512 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: spi-qcom-qspi: Fix incomplete error handling in runtime PM
CVE-2026-93269 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableext4: fix circular lock dependency in ext4_ext_migrate
CVE-2026-97502 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemmc: davinci: avoid NULL deref of host->data in IRQ handler
CVE-2026-93245 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableapparmor: policy_int make sure list heads are initialized before fail path
CVE-2026-97473 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepowercap: intel_rapl: Fix memory leak in rapl_add_package_cpuslocked()
CVE-2026-93243 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/secretmem: properly account locked pages
CVE-2026-93283 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei3c: master: Fix device_register() error path
CVE-2026-93239 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablearm64: mm: Fix the lockless page-table walk in show_pte()
CVE-2026-97476 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablerds: filter RDS_INFO_* getsockopt by caller's netns
CVE-2026-93236 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemedia: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common
CVE-2026-93829 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fix races in cifsd thread creation
CVE-2026-93281 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: rtw89: fix HE extended capability length check
CVE-2026-97493 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: Bound GPIO I2C table entry count from VBIOS
CVE-2026-93252 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableocfs2: fix circular locking dependency in ocfs2_init_acl()
CVE-2026-93273 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableregulator: tps6594: Fix device node reference leaks in multiphase loop
CVE-2026-97472 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv6: addrconf: fix temp address generation after prefix deprecation
CVE-2026-97521 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegfs2: fix quota init duplicate scan
CVE-2026-93802 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: rsi: validate beacon length before fixed buffer copy
CVE-2026-53493 ↗azl3 moby-containerd-cc 1.7.7-17 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableContainerd has image-pull DoS via crafted OCI index graph amplification
CVE-2026-97453 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableACPICA: validate byte_count in acpi_ps_get_next_package_length()
CVE-2026-93274 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepinctrl: bcm2835: Don't remove an unregistered GPIO chip
CVE-2026-93541 ↗azl3 libXi 1.8.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOut-of-bounds read in libXi's XQueryDeviceState()
CVE-2026-93544 ↗azl3 libXi 1.8.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOut-of-bounds read in libXi's XI2 XIQueryDevice reply parsing
CVE-2026-93788 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: acpi: validate WGDS table revision index
CVE-2026-93542 ↗azl3 libXi 1.8.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOut-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes()
CVE-2026-97440 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: qrtr: fix node refcount leak on ctrl packet alloc failure
CVE-2026-94281 ↗azl3 libXi 1.8.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOut-of-bounds read in libXi's XListInputDevices() class parsing
CVE-2026-97516 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result()
CVE-2026-93545 ↗azl3 libXi 1.8.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOut-of-bounds read in libXi's XListInputDevices()
CVE-2026-97490 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaffs: handle set_blocksize failures
CVE-2026-93223 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablestaging: media: tegra-video: fix of_node_put() on VIP parse errors
CVE-2026-97492 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed
CVE-2026-97484 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusbip: vhci_hcd: fix NULL deref in status_show_vhci
CVE-2026-97511 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: avoid out-of-bounds access in monitor
CVE-2026-97408 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: L2CAP: validate connectionless PSM length
CVE-2026-93268 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableext4: skip extra isize expansion during mount to prevent deadlock
CVE-2026-97504 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewatchdog: lenovo_se10_wdt: Fix use-after-free and resource leak risk
CVE-2026-100074 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Mark bpf_refcount field as unique
CVE-2026-97424 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu/ras: add ras_suspend callback and use it for cp_ecc_error_irq
CVE-2026-93278 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablestaging: octeon: add missing napi_disable in cvm_oct_rx_shutdown
CVE-2026-97489 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebfs: handle set_blocksize failures
CVE-2026-97506 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: ixp4xx - fix buffer chain unwind on allocation failure
CVE-2026-93825 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: Add NULL check for spi_get_device_id() in spi_get_device_match_data()
CVE-2026-98159 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: mt7921: validate CLC firmware records
CVE-2026-97456 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableACPICA: Fix condition check in acpi_ps_parse_loop()
CVE-2026-97427 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/pm: bound pp_dpm_set_pp_table() memcpy
CVE-2026-93205 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiommu/arm-smmu-v3: Manage teardown with devm
CVE-2026-93823 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl
CVE-2026-98007 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Reject non-scalar bpf_loop iteration counts
CVE-2026-97481 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableserial: 8250: fix possible ISR soft lockup
CVE-2026-97559 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fail DACL rewrite when the new DACL exceeds 64K
CVE-2026-93286 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: appletalk: fix NULL pointer dereference in aarp_send_ddp()
CVE-2026-93797 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: mvm: fix an off-by-1 boundary check
CVE-2026-93784 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()
CVE-2026-98158 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableppp_async: drop the errored frame instead of resetting its headroom
CVE-2026-93811 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling
CVE-2026-97958 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain().
CVE-2026-97500 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: rtw89: phy: check length before parsing PHY status IE
CVE-2026-98109 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_core: Fix race condition during device registration
CVE-2026-97936 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: Fix memory corruption from the histogram stacktrace modifier
CVE-2026-98097 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletipc: Dont send random pad bytes in RESET/ACTIVATE messages
CVE-2026-98080 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: do not force reloc root creation during qgroup_account_snapshot()
CVE-2026-98008 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: macb: fix NULL pointer dereference on unbind with fixed-link
CVE-2026-93822 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePCI: iproc: Protect root bus removal with rescan lock
CVE-2026-93800 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()
CVE-2026-97981 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: ethernet: cortina: Count dropped frames as NAPI work
CVE-2026-97411 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: ibm: emac: mal: fix potential system hang in mal_remove()
CVE-2026-97499 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecoresight: perf: Retrieve path and source from event data
CVE-2026-98111 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: btintel: validate version TLV value lengths
CVE-2026-97446 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableACPICA: Fix NULL pointer dereference in acpi_ns_custom_package()
CVE-2026-97418 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: es18xx: check control allocation before private data setup
CVE-2026-98016 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: Fix use-after-free race in sample_restore_put()
CVE-2026-97908 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev
CVE-2026-93219 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableclocksource/drivers/timer-sun4i: Advertise a real minimum delta
CVE-2026-97567 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemptcp: prevent race between disconnect() and rtx
CVE-2026-98064 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix NULL-ptr-deref when showing a void BTF type
CVE-2026-97494 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: validate and share PSP fw_pri_buf copies via psp_copy_fw
CVE-2026-97495 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: Check bounds on allocate_doorbell
CVE-2026-97599 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableieee802154: hwsim: serialize pib updates to fix double-free
CVE-2026-97975 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_sysfs: Fix NULL pointer dereference in device_del()
CVE-2026-97539 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: xusbatm: don't rely on id table pointer arithmetic
CVE-2026-97412 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepds_core: quiesce DMA before freeing resources
CVE-2026-97485 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableomfs: handle set_blocksize failures
CVE-2026-97596 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipvs: reject invalid states in connection template sync records
CVE-2026-97510 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablethunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response()
CVE-2026-97925 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletick/broadcast: Plug clockevents replacement race
CVE-2026-98075 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: reject BPF_PSEUDO_FUNC reference to the main program
CVE-2026-97519 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/xe: Fix null pointer dereference in devcoredump cleanup
CVE-2026-97597 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv6: flowlabel: cap duplicate leases per socket
CVE-2026-98090 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: restore active device pointers after failed sprout
CVE-2026-97998 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nfnetlink_log: cope with concurrent instance destruction
CVE-2026-97960 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableperf/x86/intel: Prevent drain_pebs() reentry
CVE-2026-97906 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebootconfig: Fix integer overflow in initrd size check
CVE-2026-97985 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaf_unix: Update last skb marker in manage_oob().
CVE-2026-97619 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableio_uring/rw: end write accounting from ->ki_complete
CVE-2026-98121 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewatchdog: msc313e: Fix NULL pointer dereference in PM callbacks
CVE-2026-97439 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib
CVE-2026-98021 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: reject oversized tx_queue_len at netlink parse time
CVE-2026-98031 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenexthop: Initialize extack in remove_nh_grp_entry()
CVE-2026-97514 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemedia: chips-media: wave5: Fix Reports from Kernel Lock Validator
CVE-2026-97964 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableppp_synctty: ensure a writeable skb header
CVE-2026-93812 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr
CVE-2026-97993 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx
CVE-2026-97905 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecpufreq: zero-initialize policy cpumask before sysfs publication
CVE-2026-97952 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesunvdc: unmap LDC cookies when the descriptor send fails
CVE-2026-97534 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: accurately adjust free_sections during free_segment_range
CVE-2026-97554 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()
CVE-2026-97529 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[]
CVE-2026-97530 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: qla2xxx: Fix soft lockup polling continuation IOCB signature
CVE-2026-97488 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableqnx4: handle set_blocksize failures
CVE-2026-97568 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemptcp: syncookies: remember the request backup flag
CVE-2026-98020 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepds_core: fix cmd_regs access racing BAR unmap on reset
CVE-2026-97517 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: nl80211: reject beacons with bad HE operation
CVE-2026-97600 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableieee802154: cc2520: fix FIFOP work use-after-free
CVE-2026-97434 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledpaa2-switch: fix handling of NAPI on the remove path
CVE-2026-97918 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: Undo the registration when enabling the histogram trigger fails
CVE-2026-97607 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevdpa: ifcvf: Put device on unsupported feature error
CVE-2026-93808 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: usb-audio: caiaq: validate EP1 reply lengths
CVE-2026-97939 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipmr: account multicast table and route memory
CVE-2026-97556 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: avoid leaking refcount when cifs_sb_tlink() fails
CVE-2026-93828 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableexfat: fix handling of damaged volume in exfat_create_upcase_table()
CVE-2026-97969 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewatchdog: msc313e: Fix clock leak and spurious timer in settimeout()
CVE-2026-98019 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: mark a NULL call argument precise
CVE-2026-93805 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: cfg80211: validate rx/tx MLME callback frame lengths before access
CVE-2026-98086 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: ump: do not touch legacy_rmidi before it exists
CVE-2026-98043 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Don't infer non-NULL from a pointer with an unbounded offset
CVE-2026-97994 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevhost/vdpa: reject VRING_NUM larger than device max
CVE-2026-98066 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: caiaq: Fix potential double-free at error path
CVE-2026-98026 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: bridge: mcast: properly convert mglist to rcu
CVE-2026-98072 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/rds: use wq_has_sleeper() in release_in_xmit()
CVE-2026-98078 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipvs: fix reversed sequence option serialization
CVE-2026-97419 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablehsr: broadcast netlink notifications in the device's net namespace
CVE-2026-97987 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevirtio_input: reset device if input_register_device() fails
CVE-2026-98085 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge
CVE-2026-97933 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: Take trace_array reference when opening a tracer options file
CVE-2026-93815 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: au1000: move free_irq out of the close-time spinlocked section
CVE-2026-97425 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: fix buffer overflow during vBIOS update
CVE-2026-97917 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaccel/ivpu: Validate full buffer range in ivpu_to_cpu_addr
CVE-2026-98014 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5: E-Switch, prevent mc_list repopulation during vport disable
CVE-2026-97518 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: cfg80211: reject duplicate wiphy cipher suite entries
CVE-2026-98162 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb/server: fix tree connection leak in smb2_tree_connect()
CVE-2026-98012 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: sfq: clamp quantum in change path
CVE-2026-97432 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: mvm: fix P2P-Device binding handling
CVE-2026-98113 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: rate limit unmapped SID errors
CVE-2026-97605 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableerofs: preserve LZMA decoders on resize failure
CVE-2026-97616 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: act_api: release all action references on NEWACTION failure
CVE-2026-98046 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Mark bpf_btf_find_by_name_kind() as sleepable
CVE-2026-98024 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailables390/ism: folio_put() after error
CVE-2026-97416 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk()
CVE-2026-98129 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add()
CVE-2026-98003 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiommu/amd: Do not reallocate GA log buffers on resume
CVE-2026-97989 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevduse: validate virtqueue alignment
CVE-2026-97491 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/rds: Don't sleep inside rds_ib_conn_path_shutdown
CVE-2026-98098 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletipc: fix NULL deref in tipc_named_node_up() on empty publication list
CVE-2026-98161 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvdimm: pmem: keep PREFLUSH before data writes
CVE-2026-97965 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevxlan: initialize _md in vxlan_xmit_one()
CVE-2026-97592 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailables390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm
CVE-2026-97920 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: Keep the entry count when the histogram stats allocation fails
CVE-2026-98034 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Mark NULL kptr stores precise
CVE-2026-98077 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()
CVE-2026-93818 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePCI: plda: Protect root bus removal with rescan lock

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-54423trackedCVSS 6.5Red Hat OpenShift Container Platform 4.20registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:3ed82adddc3da003bdb272e2a5df0317abe41512179cba925f65fb5d8f7c2eb3_amd64Patch ↗Advisory ↗
Red HatCVE-2026-54423trackedCVSS 6.5Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:6718b02456caee6be9a4f7306379f11f45a357d1ba03b893c1aafb614cae00bd_arm64Patch ↗Advisory ↗
SuseCVE-2026-56852trackedCVSS 5.9Open Enterprise Server 23.4terraform-provider-aws-0:3.11.0-150200.6.24.2.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-58469trackedCVSS 6.5Red Hat Enterprise Linux AppStream (v. 8)wget-0:1.19.5-16.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59884trackedCVSS 5.9Red Hat Enterprise Linux AI 3.3registry.redhat.io/rhelai3/disk-image-cuda-rhel9@sha256:c89a11f9d1f3ec913be22a418b9d7667f6cda2aa7dd0556c796c90c1fc785096_amd64Patch ↗Advisory ↗
Red HatCVE-2026-59884trackedCVSS 5.9Red Hat Enterprise Linux AI 3.3registry.redhat.io/rhelai3/bootc-aws-cuda-rhel9@sha256:db445687f68381ba4348925b32b7782fb3424eefd0a6e58e200a9ad69685551a_amd64Patch ↗Advisory ↗
SuseCVE-2026-63800trackedCVSS 6.4SUSE Liberty Linux 10kernel-0:6.12.0-211.50.1.el10_2.x86_64no patch linkAdvisory ↗
SuseCVE-2026-64018trackedCVSS 5.9SUSE Liberty Linux 10kernel-0:6.12.0-211.50.1.el10_2.x86_64no patch linkAdvisory ↗
SuseCVE-2026-64136trackedCVSS 5.8SUSE Liberty Linux 10kernel-0:6.12.0-211.50.1.el10_2.x86_64no patch linkAdvisory ↗
Red HatCVE-2026-64276trackedCVSS 6.4Red Hat Enterprise Linux AppStream (v. 10)kernel-64k-debug-debuginfo-0:6.12.0-211.50.1.el10_2.aarch64Patch ↗Advisory ↗
SuseCVE-2026-64276trackedCVSS 5.5SUSE Liberty Linux 10kernel-0:6.12.0-211.50.1.el10_2.x86_64no patch linkAdvisory ↗
Red HatCVE-2026-64277trackedCVSS 6.4Red Hat Enterprise Linux AppStream (v. 10)kernel-64k-debug-debuginfo-0:6.12.0-211.50.1.el10_2.aarch64Patch ↗Advisory ↗
SuseCVE-2026-64277trackedCVSS 5.5SUSE Liberty Linux 10kernel-0:6.12.0-211.50.1.el10_2.x86_64no patch linkAdvisory ↗
SuseCVE-2026-64298trackedCVSS 5.5SUSE Liberty Linux 10kernel-0:6.12.0-211.50.1.el10_2.x86_64no patch linkAdvisory ↗
SuseCVE-2026-64438trackedCVSS 5.5SUSE Liberty Linux 10kernel-0:6.12.0-211.50.1.el10_2.x86_64no patch linkAdvisory ↗
SuseCVE-2026-64490trackedCVSS 5.5SUSE Liberty Linux 10kernel-0:6.12.0-211.50.1.el10_2.x86_64no patch linkAdvisory ↗
SuseCVE-2026-64611trackedCVSS 6.5SUSE Linux Enterprise High Performance Computing 12 SP5cups-filters-0:1.0.58-19.38.1.x86_64no patch linkAdvisory ↗
SuseCVE-2026-64612trackedCVSS 5.3SUSE Linux Enterprise High Performance Computing 12 SP5cups-filters-0:1.0.58-19.38.1.x86_64no patch linkAdvisory ↗
SuseCVE-2026-72130trackedCVSS 5.5SUSE Liberty Linux 10kernel-0:6.12.0-211.50.1.el10_2.x86_64no patch linkAdvisory ↗
SuseCVE-2026-79088trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:152.0.7977.64-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-79293trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:152.0.7977.64-bp160.1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2024-45336CVSS 5.9Red Hat Enterprise Linux AppStream E4S (v.8.8)git-lfs-0:3.2.0-2.el8_8.8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2024-45336CVSS 5.9Red Hat Enterprise Linux AppStream AUS (v.8.6)git-lfs-0:2.13.3-3.el8_6.8.srcPatch ↗Advisory ↗

Glossary