CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Vulnerabilities

September 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 2 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 5,936 vulnerabilities across 17,974 returned patch records from 5 vendors. Filter the month to date, or browse the static page trail without JavaScript.

17,974all patch recordsClear filters1,064criticalShow these records2Microsoft exploitation detectedShow these records4Microsoft in the Known Exploited Vulnerabilities catalogShow these records14,542tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 81 of 90 · records 16,001 to 16,200 of 17,974

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-87910 ↗azl3 python3 3.12.14-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletarfile hardlink fallback ignores custom extraction filter rejection via None
CVE-2026-19941 ↗azl3 bind 9.20.26-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecheckwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof
CVE-2026-19662 ↗azl3 bind 9.20.26-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableqpcache NOQNAME proof use-after-free crashes recursive resolver
CVE-2026-19668 ↗azl3 bind 9.20.26-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableResource Exhaustion via Excessive DNSSEC Cryptographic Material Matching
CVE-2026-78301 ↗azl3 bind 9.20.26-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOut-of-zone database nodes can become authoritative zone cuts
CVE-2026-69186 ↗azl3 fluent-bit 3.1.10-7 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablec-ares: Memory-amplification denial of service via unvalidated DNS header record counts
CVE-2026-93062 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments
CVE-2026-93067 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/bridge: tc358767: clamp the reported AUX read size to the request
CVE-2026-90106 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: bridge: arp/nd proxy: fix reading neigh ha
CVE-2026-90208 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableclocksource/drivers/samsung_pwm: Switch to raw_spinlock_t type
CVE-2026-93064 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser
CVE-2026-93183 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/lima: call drm_mm_init() with a valid allocation range
CVE-2026-90154 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: scope session state changes to bound connections
CVE-2026-90415 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/cxgb4: free STAG index when TPT entry write fails
CVE-2026-93073 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledax: read holder_ops once in dax_holder_notify_failure()
CVE-2026-93086 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefirmware: arm_scmi: Avoid IDR updates while cleaning channels
CVE-2026-93156 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: rk3288 - fail ahash requests on HASH idle timeout
CVE-2026-93142 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablethermal/drivers/rcar: Fix error checking in probe()
CVE-2026-90281 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablephy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend
CVE-2026-90389 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd: scope memalloc_noio to allocation critical sections
CVE-2026-92503 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableext4: fix ABBA deadlock in ext4_xattr_inode_cache_find()
CVE-2026-90417 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry()
CVE-2026-93091 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefirmware: arm_scmi: Quiesce notifications before teardown
CVE-2026-93103 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/hfi1: Preserve unit 0 on allocation failure
CVE-2026-90364 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableACPI: processor: Unregister cpufreq notifier on init failure
CVE-2026-90226 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenfc: llcp: avoid userspace overflow on invalid optlen
CVE-2026-93097 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecxl/mbox: Break poison list loop on an empty payload
CVE-2026-90333 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm-integrity: replace forgeable discard filler with a keyed sector marker
CVE-2026-90362 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/msm/dsi: Drop dev_pm_opp_set_rate(0)
CVE-2026-90150 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepnfs/blocklayout: Fix device leaks on parse failure
CVE-2026-90346 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: nl80211: clean up color-change beacon data on errors
CVE-2026-90411 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request
CVE-2026-93104 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/rvt: Return NULL after port allocation failure
CVE-2026-92520 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Zero queue and stack outputs on lock failure
CVE-2026-93149 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211_hwsim: avoid NULL skb in stop queue drain
CVE-2026-90213 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefirewire: core: fix memory leak in error path of build_tree()
CVE-2026-90170 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: validate ipc response length before dereferencing its fields
CVE-2026-90109 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue
CVE-2026-93186 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecxl/mbox: Clamp mailbox output allocation to the payload size
CVE-2026-93048 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()
CVE-2026-90156 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: safely discard unregistered deferred locks
CVE-2026-90056 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: fec: only stop PTP if it was initialized
CVE-2026-93047 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/v3d: Associate BOs with every job that accesses them
CVE-2026-90250 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf, cgroup: Fix storage null-ptr-deref after replacing prog
CVE-2026-90206 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvmet: fix max_qid race between configfs and controller allocation
CVE-2026-90370 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config
CVE-2026-93072 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableirqchip/renesas-irqc: Fix generic interrupt chip leak on remove
CVE-2026-90352 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: mt7915: release hif2 reference on probe IRQ failure
CVE-2026-90297 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/sun4i: crtc: Propagate layer initialization error
CVE-2026-90314 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableremoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()
CVE-2026-90366 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV
CVE-2026-90130 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevdpa_sim: fix cleanup after worker creation failure
CVE-2026-90274 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecoresight: etm4x: fix underflow for usage of (nrseqstate - 1)
CVE-2026-93050 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove
CVE-2026-90265 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: defrag: fix deadlock between defrag and delalloc space reservation
CVE-2026-90318 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefat: release buffer head after rebuilding parent
CVE-2026-93055 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableUDF symlink pathComponent header OOB read
CVE-2026-90202 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers
CVE-2026-90300 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Clear buf on error in __bpf_get_task_stack
CVE-2026-90184 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenull_blk: serialize configfs attribute updates with device setup
CVE-2026-90245 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefbdev: kyro: Validate overlay viewport coordinates
CVE-2026-90119 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: ice1712: Fix the card leak at probe error with the auto-cleanup
CVE-2026-90264 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: always wait for ordered extents to avoid OE races
CVE-2026-79705 ↗azl3 libcontainers-common 20240213-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePodman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers
CVE-2026-92493 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active
CVE-2026-90218 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/cma: Fix WARNING in res_to_rt
CVE-2026-93117 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: fix UAF when probe runs concurrent to dyn ID removal
CVE-2026-90285 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: qla2xxx: Remove redundant VPD flash read in sysfs read path
CVE-2026-90391 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelib/test_hmm: fail dmirror_fault() when the mirrored mm is gone
CVE-2026-77409 ↗azl3 keda 2.14.1-19 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel Blocking
CVE-2026-90330 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHID: logitech-hidpp: Fix FF device cleanup on init failure
CVE-2026-90066 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesamples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify
CVE-2026-90148 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease()
CVE-2026-93090 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefirmware: arm_scmi: Clean up channels on setup failure
CVE-2026-90073 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: hhf: clamp quantum before hhf_change() to avoid overflow
CVE-2026-93145 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableclk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister()
CVE-2026-90282 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablephy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend
CVE-2026-90395 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepower: supply: isp1704_charger: cancel work on remove
CVE-2026-90108 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition
CVE-2026-93179 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read
CVE-2026-90182 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableblk-iocost: clear delay state when freeing policy data
CVE-2026-92494 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableext4: fix buffer_head leak in ext4_init_orphan_info
CVE-2026-90078 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: act_skbmod: fix length calculations and avoid invalid header warnings
CVE-2026-90280 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablephy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend
CVE-2026-90394 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepower: supply: sc2731_charger: cancel work on remove
CVE-2026-93099 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefs/resctrl: Fix UAF from worker threads when domains are removed
CVE-2026-90088 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop
CVE-2026-93092 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefirmware: arm_scmi: Unregister device notifier before IDR teardown
CVE-2026-92523 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/nldev: validate dynamic counter attribute length
CVE-2026-90418 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch
CVE-2026-92519 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableriscv, bpf: Fix memory leak in bpf_jit_free
CVE-2026-90166 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request()
CVE-2026-90397 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefirmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published
CVE-2026-90124 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableirqchip/renesas-rzg2l: Fix loss of interrupt
CVE-2026-90284 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefirmware_loader: do not queue completed sysfs fallback requests
CVE-2026-90126 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablertc: pcf8563: fix clock provider leak on unbind
CVE-2026-90098 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: sparx5: fix sleep in atomic context in MAC table access
CVE-2026-93202 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei3c: master: Fix recursive locking during device registration
CVE-2026-90107 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/smc: free pending qentry in smc_llc_flow_stop() before memset
CVE-2026-90307 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ
CVE-2026-92476 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: keembay - Initialize completion before requesting IRQ
CVE-2026-93200 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei3c: master: Fix use-after-free of master->this
CVE-2026-93160 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: atmel-ecc - reject hardware ECDH without a public key
CVE-2026-90374 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]
CVE-2026-93058 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/msm: Only fini scheduler after successful init
CVE-2026-93114 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableplatform/surface: acpi-notify: Check ACPI companion before use
CVE-2026-93129 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableplatform/x86: dell-wmi-base: Fix handling of ultra performance key
CVE-2026-90313 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed
CVE-2026-92484 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecxl/region: Fix use-after-free in find_pos_and_ways() error path
CVE-2026-90319 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablerapidio: clear mport->net when rio_add_net() fails
CVE-2026-90074 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: fq_pie: clamp default quantum to avoid signed overflow
CVE-2026-90368 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: mt7915: unwind state on add_interface failure
CVE-2026-93188 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHID: roccat: bound device-supplied profile index
CVE-2026-92477 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: ufs: debugfs: Reserve space for a string terminator
CVE-2026-90298 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/sun4i: tcon: Drop TCON TOP device reference
CVE-2026-81871 ↗azl3 azurelinux-image-tools 1.6.0-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
CVE-2026-93185 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableASoC: rt700-sdw: always drain jack work on remove
CVE-2026-93052 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemisc: bcm-vk: Use acquire/release for msgq_inited
CVE-2026-90175 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer
CVE-2026-93150 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecgroup/cpuset: Make nr_deadline_tasks an atomic_t
CVE-2026-93118 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: aspeed_udc: check endpoint DMA allocation
CVE-2026-90251 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: MSFT: validate evt_prefix_len against the response length
CVE-2026-90075 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: fq_codel: clamp default quantum and mtu
CVE-2026-8674 ↗azl3 glibc 2.38-21 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAssertion failure in the DNS stub resolver with a long search domain

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-19730CVSS 4.2Red Hat Enterprise Linux AppStream (v. 10)podman-7:5.8.2-9.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32591CVSS 5.2Red Hat Quay 3.14registry.redhat.io/quay/quay-rhel8@sha256:5ab9413d3b6291049d4d2e6c4f3b1ac0db9587e5ea946e1853f60eabed49d8bd_s390xPatch ↗Advisory ↗
Red HatCVE-2026-42502CVSS 6.1Red Hat OpenShift Container Platform 4.20registry.redhat.io/openshift4/ose-powervs-block-csi-driver-rhel9@sha256:b10b099edfd5e1e68d3cd5cbd37325adc23aa3d3b6339981dfc53ad10edb6ab2_amd64Patch ↗Advisory ↗
Red HatCVE-2026-54515CVSS 5.3Red Hat JBoss EAP 8.1 for RHEL 8eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el8eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-54515CVSS 5.3Red Hat JBoss EAP 8.1 for RHEL 9eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el9eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-54515CVSS 5.3Red Hat JBoss EAP 8.1 for RHEL 10eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el10eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-5704CVSS 5.0Red Hat Enterprise Linux BaseOS (v. 8)tar-2:1.30-13.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59889CVSS 6.5Red Hat JBoss EAP 8.1 for RHEL 8eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el8eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-59889CVSS 6.5Red Hat JBoss EAP 8.1 for RHEL 9eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el9eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-59889CVSS 6.5Red Hat JBoss EAP 8.1 for RHEL 10eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el10eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-69153CVSS 5.3Red Hat Quay 3.14registry.redhat.io/quay/quay-rhel8@sha256:5ab9413d3b6291049d4d2e6c4f3b1ac0db9587e5ea946e1853f60eabed49d8bd_s390xPatch ↗Advisory ↗
Red HatCVE-2026-73433CVSS 6.6Red Hat Enterprise Linux Server (v. 7 ELS)gstreamer1-plugins-good-0:1.10.4-4.el7_9.3.i686Patch ↗Advisory ↗
Red HatCVE-2026-85511CVSS 4.2Red Hat JBoss EAP 8.1 for RHEL 8eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el8eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-85511CVSS 4.2Red Hat JBoss EAP 8.1 for RHEL 9eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el9eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-85511CVSS 4.2Red Hat JBoss EAP 8.1 for RHEL 10eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el10eap.noarchPatch ↗Advisory ↗
Red HatCVE-2024-45336CVSS 5.9Red Hat Enterprise Linux AppStream AUS (v.8.6)osbuild-composer-0:46.3-8.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2024-9355CVSS 6.5Red Hat Enterprise Linux AppStream AUS (v.8.6)osbuild-composer-0:46.3-8.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2025-22866CVSS 5.3Red Hat Enterprise Linux AppStream AUS (v.8.6)osbuild-composer-0:46.3-8.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-15792CVSS 6.5Red Hat Quay 3.16registry.redhat.io/quay/quay-rhel9@sha256:87d9fe47faea904645aa6ec202f28765fa9a710d3dfe3ccfeb3ca46b5a5d5d67_arm64Patch ↗Advisory ↗
Red HatCVE-2026-15927CVSS 6.8Red Hat Quay 3.16registry.redhat.io/quay/quay-rhel9@sha256:87d9fe47faea904645aa6ec202f28765fa9a710d3dfe3ccfeb3ca46b5a5d5d67_arm64Patch ↗Advisory ↗
Red HatCVE-2026-28417CVSS 4.4Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)vim-2:7.4.629-5.el6_10.4.srcPatch ↗Advisory ↗
Red HatCVE-2026-28421CVSS 5.3Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)vim-2:7.4.629-5.el6_10.4.srcPatch ↗Advisory ↗
Red HatCVE-2026-35177CVSS 4.1Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)vim-2:7.4.629-5.el6_10.4.srcPatch ↗Advisory ↗
Red HatCVE-2026-42502CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)osbuild-composer-0:165.1-5.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-43804CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)webkit2gtk3-0:2.54.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-50252CVSS 6.5Red Hat Enterprise Linux AppStream (v. 8)python3-unbound-0:1.16.2-5.14.el8_10.2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-54231CVSS 5.5Red Hat Enterprise Linux AppStream AUS (v.8.6)abrt-0:2.10.9-25.el8_6.2.srcPatch ↗Advisory ↗
Red HatCVE-2026-54231CVSS 5.5Red Hat Enterprise Linux AppStream AUS (v.8.4)abrt-0:2.10.9-25.el8_4.2.srcPatch ↗Advisory ↗
Red HatCVE-2026-54231CVSS 5.5Red Hat Enterprise Linux AppStream E4S (v.8.8)abrt-0:2.10.9-25.el8_8.2.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-57455CVSS 4.7Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)vim-2:7.4.629-5.el6_10.4.srcPatch ↗Advisory ↗
Red HatCVE-2026-59296CVSS 5.9Red Hat Data Grid 8.6.3Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-59858CVSS 6.5Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)vim-2:7.4.629-5.el6_10.4.srcPatch ↗Advisory ↗
Red HatCVE-2026-59995CVSS 5.4Red Hat Enterprise Linux AppStream (v. 10)openssh-askpass-0:9.9p1-27.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59995CVSS 5.4Red Hat Enterprise Linux AppStream (v. 9)openssh-askpass-0:9.9p1-11.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59995CVSS 5.4Red Hat Enterprise Linux AppStream (v. 8)openssh-askpass-0:8.0p1-33.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-64728CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)webkit2gtk3-0:2.54.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-64730CVSS 4.3Red Hat Enterprise Linux AppStream (v. 9)webkit2gtk3-0:2.54.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-64753CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)webkit2gtk3-0:2.54.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-64778CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)webkit2gtk3-0:2.54.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6862CVSS 5.5Red Hat Hardened Imagesefivar-0:39-13.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-71225CVSS 6.5Red Hat Enterprise Linux BaseOS EUS (v. 10.0)libkcapi-0:1.5.0-6.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-71227CVSS 5.1Red Hat Enterprise Linux BaseOS EUS (v. 10.0)libkcapi-0:1.5.0-6.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-73282CVSS 5.6Red Hat Enterprise Linux AppStream (v. 10)openssh-askpass-0:9.9p1-27.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-73282CVSS 5.6Red Hat Enterprise Linux AppStream (v. 9)openssh-askpass-0:9.9p1-11.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-73282CVSS 5.6Red Hat Enterprise Linux AppStream (v. 8)openssh-askpass-0:8.0p1-33.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-73283CVSS 5.4Red Hat Enterprise Linux AppStream (v. 10)openssh-askpass-0:9.9p1-27.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-73283CVSS 5.4Red Hat Enterprise Linux AppStream (v. 9)openssh-askpass-0:9.9p1-11.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-73433CVSS 6.6Red Hat Enterprise Linux AppStream E4S (v.8.8)gstreamer1-plugins-good-0:1.16.1-5.el8_8.3.i686Patch ↗Advisory ↗
Red HatCVE-2026-8674CVSS 5.3Red Hat Hardened Imagescompat-libpthread-nonshared-0:2.43-8.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-92030CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.16.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-92030CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.16.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-92031CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.16.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-92031CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.16.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-28374CVSS 4.3Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-28376CVSS 6.5Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-28379CVSS 6.5Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-28380CVSS 6.5Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-28383CVSS 6.5Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33378CVSS 6.5Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33380CVSS 6.3Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33381CVSS 5.9Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-50229CVSS 5.4Red Hat Enterprise Linux AppStream (v. 10)tomcat9-1:9.0.120-1.el10_2.noarchPatch ↗Advisory ↗
Red HatCVE-2026-55955CVSS 4.2Red Hat Enterprise Linux AppStream (v. 10)tomcat9-1:9.0.120-1.el10_2.noarchPatch ↗Advisory ↗
Red HatCVE-2026-55956CVSS 6.5Red Hat Enterprise Linux AppStream (v. 10)tomcat9-1:9.0.120-1.el10_2.noarchPatch ↗Advisory ↗
Red HatCVE-2026-61709CVSS 5.3Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-71557CVSS 6.3Red Hat Hardened Imagesgrype-0:0.119.0-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-71557CVSS 6.3Red Hat Hardened Imagessyft-0:1.52.0-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-7210CVSS 5.3Red Hat Hardened Imagespython3.10-0:3.10.21-1.4.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-73433CVSS 6.6Red Hat Enterprise Linux AppStream E4S (v.9.4)gstreamer1-plugins-good-0:1.22.1-4.el9_4.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-81871CVSS 6.5Red Hat Hardened Imagesgrafana12.4-0:12.4.10-0.6.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-81871CVSS 6.5Red Hat Hardened Imagestempo2.10-0:2.10.8-0.3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-81871CVSS 6.5Red Hat Hardened Imagesopentofu1.12-0:1.12.6-0.3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-81871CVSS 6.5Red Hat Hardened Imagesjaeger-0:2.20.0-0.9.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-81871CVSS 6.5Red Hat Hardened Imagestempo3.0-0:3.0.3-0.3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-81871CVSS 6.5Red Hat Hardened Imagesgrafana13.1-0:13.1.6-0.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-81871CVSS 6.5Red Hat Hardened Imagesloki3.6-0:3.6.17-0.2.hum1@aarch64Patch ↗Advisory ↗

Glossary