{
  "day": "2026-07-25",
  "boundary": "UTC calendar day",
  "published_count": 284,
  "by_severity": {
    "CRITICAL": 25,
    "HIGH": 111,
    "MEDIUM": 21,
    "LOW": 0
  },
  "kev_count": 0,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 127,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-16766",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01304,
      "epss_percentile": 0.68237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Catalyst::View::Wkhtmltopdf",
      "cwe": "CWE-78",
      "title": "Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16766"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-64320",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00728,
      "epss_percentile": 0.51357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64320"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-64268",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00695,
      "epss_percentile": 0.50156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "RDMA/siw: bound Read Response placement to the RREAD length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64268"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-64269",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00679,
      "epss_percentile": 0.49551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64269"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-64303",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00675,
      "epss_percentile": 0.4942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: fsl-lpspi: terminate the RX channel on TX prepare failure path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64303"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-64257",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00672,
      "epss_percentile": 0.49269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: reject overlapping data areas in SMB2 responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64257"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-64450",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.42965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: fix out-of-bounds read in broadcast Gap ACK blocks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64450"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-14955",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00526,
      "epss_percentile": 0.42366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themehigh",
      "product": "Checkout Field Editor for WooCommerce (Pro)",
      "cwe": "CWE-22",
      "title": "Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14955"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-64319",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00524,
      "epss_percentile": 0.4224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-auth: validate reply message payload bounds against transfer length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64319"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-66373",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00503,
      "epss_percentile": 0.40958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Redis",
      "product": "Redis",
      "cwe": "CWE-415",
      "title": "Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66373"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-64355",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00502,
      "epss_percentile": 0.40912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject fragmented frames in devmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64355"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-64312",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: pcrypt - restore callback for non-parallel fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64312"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-64374",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64374"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-64399",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00491,
      "epss_percentile": 0.40237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64399"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-64430",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0049,
      "epss_percentile": 0.40162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NTB: epf: Avoid calling pci_irq_vector() from hardirq context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64430"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-64393",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.39465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: run set info with opener credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64393"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-64397",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00477,
      "epss_percentile": 0.3937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: serialize QUERY_DIRECTORY requests per file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64397"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-64459",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00475,
      "epss_percentile": 0.39204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: restore RCU grace period in tcp_ao_destroy_sock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64459"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-64394",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64394"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-64392",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00469,
      "epss_percentile": 0.38776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: use opener credentials for delete-on-close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64392"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-64281",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: wake sq waiters when the transport closes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64281"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-64390",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: track the connection owning a byte-range lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64390"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-64398",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00464,
      "epss_percentile": 0.385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: add a permission check for FSCTL_SET_ZERO_DATA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64398"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-64448",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: restrict implied bcc[0] exemption to responses without data area",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64448"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-64383",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.3806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix double-free in SMB2_flush() replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64383"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-64384",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.38062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix change notify replay double-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64384"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-64385",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.38063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix double-free in SMB2_ioctl() replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64385"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-64386",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.38062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix query_info() replay double-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64386"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-64387",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.38063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix query directory replay double-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64387"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-64391",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.38064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: use opener credentials for ADS I/O",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64391"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-64389",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: validate NTLMv2 response before updating session key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64389"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-64380",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00443,
      "epss_percentile": 0.37052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: harden POSIX SID length parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64380"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-64414",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: handle unreadable frags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64414"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-66012",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.36612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66012"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-64396",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64396"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-64437",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64437"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-64439",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0043,
      "epss_percentile": 0.36012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: krb5 - filter out async aead implementations at alloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64439"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-64435",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "audit: Fix data races of skb_queue_len() readers on audit_queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64435"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-10818",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0042,
      "epss_percentile": 0.35234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPForms",
      "product": "WPForms Pro",
      "cwe": "CWE-434",
      "title": "WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10818"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-64368",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/slab: do not limit zeroing to orig_size when only red zoning is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64368"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-64395",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00406,
      "epss_percentile": 0.34,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: require source read access for duplicate extents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64395"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-66374",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.3222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nic",
      "product": "Knot Resolver",
      "cwe": "CWE-1284",
      "title": "Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66374"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-66013",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openremote",
      "product": "openremote",
      "cwe": "CWE-639",
      "title": "OpenRemote before 1.26.2 Authentication Bypass via Console Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66013"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-64410",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: flowtable: IPIP tunnel hardware offload is not yet support",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64410"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-64523",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00359,
      "epss_percentile": 0.29134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/handshake: Take a long-lived file reference at submit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64523"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-64400",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: prevent path traversal bypass by restricting caseless retry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64400"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-64382",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix double-free in SMB2_open() replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64382"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-64522",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64522"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-64313",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: ecc - Fix carry overflow in vli multiplication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64313"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-64364",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: multitouch: fix out-of-bounds bit access on mt_io_flags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64364"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-64445",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64445"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-64379",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: mask server-provided mode to 07777 in modefromsid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64379"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-64442",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64442"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-64443",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64443"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-64444",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64444"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-64406",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: fix UAF in bt_accept_dequeue()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64406"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-64440",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB write in HT_caps_handler()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64440"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-64403",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: validate option length before reading conf opt value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64403"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-64408",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: bnep: pin L2CAP connection during netdev registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64408"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-64441",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64441"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-64366",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64366"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-64434",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64434"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-64515",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: fix MLE defragmentation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64515"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-64505",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0022,
      "epss_percentile": 0.12744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: function: rndis: add length check for header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64505"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-64452",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "6lowpan: fix NHC entry use-after-free on error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64452"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-64307",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.1224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64307"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-64308",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.1224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64308"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-64309",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.1224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64309"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-64310",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00215,
      "epss_percentile": 0.1224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: ccp - Do not initialize SNP for SEV ioctls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64310"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-64306",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00211,
      "epss_percentile": 0.116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: drbg - Fix returning success on failure in CTR_DRBG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64306"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-64337",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00211,
      "epss_percentile": 0.11601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: mtu3: unmap request DMA on queue failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64337"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-64363",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00211,
      "epss_percentile": 0.11603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: appleir: fix UAF on pending key_up_timer in remove()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64363"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-64301",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.10951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64301"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-64346",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.10952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: udc: Fix use-after-free in gadget_match_driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64346"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-15425",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yoast",
      "product": "Yoast SEO – Advanced SEO with real-time guidance and built-in AI",
      "cwe": "CWE-79",
      "title": "Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15425"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-64326",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "block: skip sync_blockdev() on surprise removal in bdev_mark_dead()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64326"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-64327",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64327"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-64328",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_fs: Fix DMA fence leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64328"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-64302",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/mm: Fix freeing of PMD-sized vmemmap pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64302"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-64314",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: chacha20poly1305 - validate poly1305 template argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64314"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-64339",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.0996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: misc: usbio: bound bulk IN response length to the received transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64339"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-64446",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00195,
      "epss_percentile": 0.09533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64446"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-64495",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00195,
      "epss_percentile": 0.09589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: gyro: bmg160: bail out when bandwidth/filter is not in table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64495"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-64325",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64325"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-64351",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00185,
      "epss_percentile": 0.0847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64351"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-64484",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00185,
      "epss_percentile": 0.08436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: es1938: check snd_ctl_new1() return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64484"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-64455",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: chaoskey: Fix slab-use-after-free in chaoskey_release()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64455"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-64461",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: mediatek: Fix IRQ domain leak when port fails to enable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64461"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-64462",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: altera: Fix resource leaks on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64462"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-64465",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: xhci: Fix sleep in atomic context in xhci_free_streams()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64465"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-64470",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btusb: fix use-after-free on marvell probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64470"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-64471",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btusb: fix use-after-free on registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64471"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-64478",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usb-audio: avoid kobject path lookup in DualSense match",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64478"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-64483",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: firewire: isight: bound the sample count to the packet payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64483"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-64487",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64487"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-64488",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.08368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: aoa: check snd_ctl_new1() return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64488"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-64369",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00181,
      "epss_percentile": 0.07959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390: Revert support for DCACHE_WORD_ACCESS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64369"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-64472",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00181,
      "epss_percentile": 0.07977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vfio/mlx5: Fix racy bitfields and tighten struct layout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64472"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-64479",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00181,
      "epss_percentile": 0.07977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64479"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-64480",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00181,
      "epss_percentile": 0.07977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: ice1712: check snd_ctl_new1() return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64480"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-64482",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00181,
      "epss_percentile": 0.07976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: gus: check snd_ctl_new1() return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64482"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-64454",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.07929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: dwc3: run gadget disconnect from sleepable suspend context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64454"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-64458",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.07929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/damon/ops-common: handle extreme intervals in damon_hot_score()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64458"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-64476",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.07929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vfio/pci: Latch disable_idle_d3 per device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64476"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-64486",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.0793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: cmipci: check snd_ctl_new1() return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64486"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-64489",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.0793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: ymfpci: check snd_ctl_new1() return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64489"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-64356",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00179,
      "epss_percentile": 0.07716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix memory leak in xfs_dqinode_metadir_create()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64356"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-64316",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: caam - use print_hex_dump_devel to guard key hex dumps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64316"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-64329",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64329"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-64330",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: typec: tcpm: Validate SVID index in svdm_consume_modes()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64330"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-64331",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usbip: vudc: fix NULL deref in vep_dequeue()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64331"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-64332",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: ulpi: fix memory leak on registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64332"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-64334",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: serial: digi_acceleport: fix hard lockup on disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64334"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-64335",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: serial: digi_acceleport: fix broken rx after throttle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64335"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-64338",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: misc: uss720: unregister parport on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64338"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-64340",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: legousbtower: fix use-after-free on disconnect race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64340"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-64342",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: iowarrior: fix use-after-free on disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64342"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-64343",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: ldusb: fix use-after-free on disconnect race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64343"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-64344",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: idmouse: fix use-after-free on disconnect race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64344"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-64347",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64347"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-64359",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64359"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-64360",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hfs/hfsplus: zero-initialize buffer in hfs_bnode_read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64360"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-64362",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: lg-g15: cancel pending work on remove to fix a use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64362"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-64370",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64370"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-64371",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "proc: protect ptrace_may_access() with exec_update_lock (part 1)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64371"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-64373",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq: Fix hotplug-suspend race during reboot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64373"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-64381",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: Fix next buffer leak in receive_encrypted_standard()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64381"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-64425",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64425"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-64429",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gpio: eic-sprd: use raw_spinlock_t in the irq startup path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64429"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-64494",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: light: gp2ap002: fix runtime PM leak on read error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64494"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-64497",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.0758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: chemical: scd30: Cleanup initializations and fix sign-extension bug",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64497"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-64503",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64503"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-64514",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.0758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "userfaultfd: gate must_wait writability check on pte_present()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64514"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-64474",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64474"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-64477",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64477"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-64457",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio_pci: fix vq info pointer lookup via wrong index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64457"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-64473",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vfio: Remove device debugfs before releasing devres",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64473"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-64491",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00174,
      "epss_percentile": 0.07183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usx2y: us144mkii: fix work UAF on disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64491"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-64336",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: serial: keyspan_pda: fix information leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64336"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-64345",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_printer: take kref only for successful open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64345"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-64348",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: free iso schedules on failed submit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64348"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-64350",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64350"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-64352",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Allow LPM map access from sleepable BPF programs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64352"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-64365",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: letsketch: fix UAF on inrange_timer at driver unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64365"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-64376",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware_loader: fix device reference leak in firmware_upload_register()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64376"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-64405",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64405"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-64409",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64409"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-64417",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm: shrinker: fix NULL pointer dereference in debugfs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64417"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-64419",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64419"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-64428",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gpio: sch: use raw_spinlock_t in the irq startup path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64428"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-64453",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: misc: usbio: fix disconnect UAF in client teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64453"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-64464",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xhci: sideband: fix ring sg table pages leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64464"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-64466",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rust_binder: clear freeze listener on node removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64466"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-64492",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: temperature: tmp006: use devm_iio_trigger_register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64492"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-64512",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: CPPC: Suppress UBSAN warning caused by field misuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64512"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-64513",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00171,
      "epss_percentile": 0.06824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: x86: Unconditionally recompute CR8 intercept on PPR update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64513"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-64286",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64286"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-64287",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64287"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-64305",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qat - protect service table iterations with service_lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64305"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-64321",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.0653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme: target: rdma: fix ndev refcount leak on queue connect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64321"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-64357",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix exchmaps reservation limit check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64357"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-64358",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: mtk-jpeg: cancel workqueue on release for supported platforms only",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64358"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-64377",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq: qcom-cpufreq-hw: Fix possible double free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64377"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-64404",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64404"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-64407",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64407"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-64415",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64415"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-64416",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.0654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64416"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-64421",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: nxp: imx8-isi: Fix use-after-free on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64421"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-64424",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.0654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netpoll: fix a use-after-free on shutdown path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64424"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-64427",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: logitech-dj: Fix maxfield check in DJ short report validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64427"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-64433",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64433"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-64493",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: pressure: mpl115: fix runtime PM leak on read error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64493"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-64517",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/gsc: Fix double-free of managed BO in error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64517"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-64518",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.0651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64518"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-64519",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Fix infinite loop in layout state revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64519"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-64528",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tty: serial: samsung: Remove redundant port lock acquisition in rx helpers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64528"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-64341",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: iowarrior: fix use-after-free on disconnect race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64341"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-64349",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64349"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-64353",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Keep dynamic inner array lookups nullable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64353"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-64426",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.0634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64426"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-64521",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pinctrl: meson: amlogic-a4: fix deadlock issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64521"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-64500",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00165,
      "epss_percentile": 0.06224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: adc: lpc32xx: Initialize completion before requesting IRQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64500"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-64504",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00165,
      "epss_percentile": 0.06224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: accel: bmc150: clamp the device-reported FIFO frame count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64504"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-64271",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "Input: touchwin - reset the packet index on every complete packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64271"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-64273",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "Input: iforce - bound the device-reported force-feedback effect index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64273"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-64274",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "Input: goodix - clamp the device-reported contact count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64274"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-64276",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64276"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-64277",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64277"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-64296",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "exfat: bound uniname advance in exfat_find_dir_entry()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64296"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-64304",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qat - validate RSA CRT component lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64304"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-64322",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "udf: validate sparing table length as an entry count, not a byte count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64322"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-64333",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: serial: digi_acceleport: fix write buffer corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64333"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-64280",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64280"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-64270",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.0604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "Input: mms114 - reject an oversized device packet size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64270"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-64272",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.0604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "Input: mms114 - fix touch indexing for MMS134S and MMS136",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64272"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-64293",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64293"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-64300",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/aux: Fix page UAF in map_range()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64300"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-64451",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.05956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix NULL pointer dereference in func_set_flag()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64451"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-64506",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00161,
      "epss_percentile": 0.0584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtw89: correct drop logic for malformed AMPDU frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64506"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-64527",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00161,
      "epss_percentile": 0.05751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/hyperv: validate VMBus packet size in receive callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64527"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-64266",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "fuse: re-lock request before returning from fuse_ref_folio()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64266"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-64298",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSv4: include MAY_WRITE in open permission mask for O_TRUNC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64298"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-64299",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Prevent out-of-bounds read in glob matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64299"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-64317",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "isofs: bound Rock Ridge symlink components to the SL record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64317"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-64318",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "partitions: aix: bound the pp_count scan to the ppe array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64318"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-64323",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "udf: validate VAT header length against the VAT inode size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64323"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-64265",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64265"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-64295",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64295"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-64259",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "fuse-uring: make a fuse_req on SQE commit only findable after memcpy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64259"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-64261",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64261"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-64311",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: loongson - Remove broken and unused loongson-rng",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64311"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-64499",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00157,
      "epss_percentile": 0.05385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: adc: ti-ads1119: fix PM reference leak in buffer preenable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64499"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-64507",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00157,
      "epss_percentile": 0.05386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/bugs: Enable IBPB flush on BPF JIT allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64507"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-64508",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00157,
      "epss_percentile": 0.05385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Support for hardening against JIT spraying",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64508"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-64509",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00157,
      "epss_percentile": 0.05386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rust: block: fix GenDisk cleanup paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64509"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-64324",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "udf: validate free block extents against the partition length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64324"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-64275",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-369",
      "title": "Input: elan_i2c - prevent division by zero and arithmetic underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64275"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-64297",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "module: decompress: check return value of module_extend_max_pages()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64297"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-64511",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.0534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: NFIT: core: Fix possible NULL pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64511"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-64525",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64525"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-64256",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: don't wrap around quota ids in dqiterate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64256"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-64289",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommufd: Set upper bounds on cache invalidation entry_num and entry_len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64289"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-64290",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-835",
      "title": "iommufd: Break the loop on failure in iommufd_fault_fops_read()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64290"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-64294",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm: do file ownership checks with the proper mount idmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64294"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-64498",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: buffer: hw-consumer: free scan_mask on buffer release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64498"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-64526",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00154,
      "epss_percentile": 0.05134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ethtool: tsconfig: fix missing ethnl_ops_complete()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64526"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-64490",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.04952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: virtio: Validate control metadata from the device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64490"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-64258",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64258"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-64262",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse-uring: end fuse_req on io-uring cancel task work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64262"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-64263",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse-uring: fix moving cancelled entry to ent_in_userspace list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64263"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-64264",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse-uring: fix EFAULT clobber in fuse_uring_commit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64264"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-64267",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: avoid 32-bit prune notification count wrap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64267"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-64278",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: imx-lpi2c: mark I2C adapter when hardware is powered down",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64278"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-64288",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64288"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-64291",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommufd: Set veventq_depth upper bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64291"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-64292",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "iommufd: Move vevent memory allocation outside spinlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64292"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-64456",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.0454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwrng: virtio: clamp device-reported used.len at copy_data()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64456"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-64315",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: caam - use print_hex_dump_devel to guard key hex dumps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64315"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-64524",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/hyperv: validate resolution_count and fix WIN8 fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64524"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-64367",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: hid-goodix-spi: validate report size to prevent stack buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64367"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-64475",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vfio/pci: Release the VGA arbiter client on register_device() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64475"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-64449",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: vme_user: bound slave read/write to the kern_buf size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64449"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-64463",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: typec: tcpci_rt1711h: unregister TCPCI port with devres",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64463"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-64481",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: hda/cs35l41: Fix firmware load work teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64481"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-64283",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "KVM: guest_memfd: Treat memslot binding offset+size as unsigned values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64283"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-64467",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rust_binder: use a u64 stride when cleaning up the offsets array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64467"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-64485",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.0358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: compress: Fix task creation error unwind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64485"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-64285",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: SEV: Pin source page for write when adding CPUID data for SNP guest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64285"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-64438",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64438"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-64432",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64432"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-64468",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "binder: fix UAF in binder_free_transaction()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64468"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-64469",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.0342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "binder: fix UAF in binder_thread_release()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64469"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-64529",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qat - remove unused character device and IOCTLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64529"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-64447",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: media: ipu7: fix double-free and use-after-free in error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64447"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-64422",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64422"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-64520",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64520"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-64354",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Validate BTF repeated field counts before expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64354"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-64361",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64361"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-64375",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "proc: protect ptrace_may_access() with exec_update_lock (FD links)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64375"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-64378",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64378"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-64402",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64402"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-64279",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "i2c: core: fix adapter deregistration race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64279"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-64372",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.0267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq: pcc: fix use-after-free and double free in _OSC evaluation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64372"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-64401",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: resolve SWN tcon from live registrations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64401"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-64423",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv4: igmp: remove multicast group from hash table on device destruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64423"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-64411",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: ebtables: terminate table name before find_table_lock()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64411"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-64412",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: ebtables: module names must be null-terminated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64412"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-64496",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: event: Fix event FIFO reset race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64496"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-64260",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "fuse-uring: Avoid queue->stopped races and set/read that value under lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64260"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-64418",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm: shrinker: fix shrinker_info teardown race with expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64418"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-64431",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: avoid calling post_write_mst_fixup() for invalid index_block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64431"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-64284",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-367",
      "title": "KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64284"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-64413",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: ebtables: zero chainstack array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64413"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-64388",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/client: fix chown/chgrp with SMB3 POSIX Extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64388"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-64502",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64502"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-64436",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: af_key: initialize alg_key_len for IPComp states",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64436"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-64420",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mfd: cros_ec: Delay dev_set_drvdata() until probe success",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64420"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-64460",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI/IOV: Skip VF Resizable BAR restore on read error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64460"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-64501",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: adc: ad_sigma_delta: fix CS held asserted and state leaks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64501"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-64516",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64516"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-64510",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64510"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-64282",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64282"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-66011",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66011"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-10681",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00085,
      "epss_percentile": 0.00373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-362",
      "title": "SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10681"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10681",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10681 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65693",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65693 (microweber). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65711",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65711 (nuxsmin sysPass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66004",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66004 (ahujasid blender-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66005",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66005 (janhq jan). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66027",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66027 (kortix-ai suna). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2021-27137",
      "detail": "DUE DATE PASSED — CVE-2021-27137 (DD-WRT). CISA remediation deadline was July 24, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-0770",
      "detail": "DUE DATE PASSED — CVE-2026-0770 (Langflow). CISA remediation deadline was July 24, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-63030",
      "detail": "DUE DATE PASSED — CVE-2026-63030 (WordPress). CISA remediation deadline was July 24, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
