{
  "day": "2026-09-11",
  "boundary": "UTC calendar day",
  "published_count": 703,
  "by_severity": {
    "CRITICAL": 36,
    "HIGH": 81,
    "MEDIUM": 134,
    "LOW": 11
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 441,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-8778",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00623,
      "epss_percentile": 0.47912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mulika",
      "product": "MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields.",
      "cwe": "CWE-434",
      "title": "MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8778"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-19991",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stiofansisland",
      "product": "UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP",
      "cwe": "CWE-22",
      "title": "UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19991"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-78133",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.35102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-416",
      "title": "libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78133"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-78123",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-825",
      "title": "strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78123"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-78126",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-476",
      "title": "strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78126"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-78129",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-835",
      "title": "strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78129"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-87123",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hbs",
      "product": "hbs",
      "cwe": "CWE-248",
      "title": "hbs vulnerable to Denial of Service via unhandled exception in async helper output escaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87123"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-73785",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise",
      "product": "HPE IceWall products",
      "cwe": "CWE-241",
      "title": "HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73785"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-89174",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kingdom Communication Associated",
      "product": "EH3040",
      "cwe": "CWE-307",
      "title": "Kingdom Communication Associated｜Smart Video Intercom System - Missing Burte-force Protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89174"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-78127",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00354,
      "epss_percentile": 0.28585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-401",
      "title": "libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78127"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-78135",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-841",
      "title": "libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78135"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-18561",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unitecms",
      "product": "Unlimited Elements For Elementor",
      "cwe": "CWE-89",
      "title": "Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18561"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-12215",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.2482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xootix",
      "product": "OTP Login & Register Woocommerce",
      "cwe": "CWE-434",
      "title": "OTP Login & Register Woocommerce <= 2.7.2 - Unauthenticated Authentication Bypass via Brute Force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12215"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-78134",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-863",
      "title": "strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78134"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-89175",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kingdom Communication Associated",
      "product": "EH3040",
      "cwe": "CWE-602",
      "title": "Kingdom Communication Associated｜Smart Video Intercom System - Client-Side Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89175"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-47839",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00317,
      "epss_percentile": 0.2435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "UAA",
      "cwe": "CWE-284",
      "title": "Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47839"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-78130",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-476",
      "title": "strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78130"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-78132",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-835",
      "title": "strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78132"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-87859",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "morgan",
      "product": "morgan",
      "cwe": "CWE-117",
      "title": "morgan vulnerable to Log Injection via unescaped double quote in quoted log fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87859"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-15462",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.22929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gingerplugins",
      "product": "Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons",
      "cwe": "CWE-89",
      "title": "Sticky Chat Widget <= 1.4.2 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15462"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-87908",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "multiparty",
      "product": "multiparty",
      "cwe": "CWE-400",
      "title": "multiparty vulnerable to Denial of Service via unbounded part-header accumulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87908"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-18579",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opajaap",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-79",
      "title": "WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18579"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-17037",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-79",
      "title": "Kirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17037"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-81825",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "specialk",
      "product": "Simple Ajax Chat – Add a Fast, Secure Chat Box",
      "cwe": "CWE-79",
      "title": "Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81825"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-87727",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.19926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appleple inc.",
      "product": "a-blog cms",
      "cwe": "CWE-22",
      "title": "a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87727"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-11496",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "edgarrojas",
      "product": "PDF Builder for WooCommerce. Create invoices,packing slips and more",
      "cwe": "CWE-862",
      "title": "Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11496"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-89173",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kingdom Communication Associated",
      "product": "EH3040",
      "cwe": "CWE-204",
      "title": "Kingdom Communication Associated｜Smart Video Intercom System - Sensitive Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89173"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-19985",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "comesio",
      "product": "Relevanssi – A Better Search",
      "cwe": "CWE-79",
      "title": "Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19985"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-77150",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.16882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unitecms",
      "product": "Unlimited Elements For Elementor",
      "cwe": "CWE-79",
      "title": "Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77150"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-89176",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Howyar",
      "product": "WeenyGenius",
      "cwe": "CWE-306",
      "title": "Howyar｜WeenyGenius - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89176"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-19486",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.15998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Gemini Enterprise Agent Platform App Builder",
      "cwe": "CWE-918",
      "title": "SSRF in Gemini Enterprise Agent Platform App Builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19486"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-81754",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.1522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fernandot",
      "product": "Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…",
      "cwe": "CWE-79",
      "title": "Vigilant <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81754"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-6640",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dglingren",
      "product": "Media Library Assistant",
      "cwe": "CWE-79",
      "title": "Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6640"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-89092",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The GNU C Library",
      "product": "glibc",
      "cwe": "CWE-789",
      "title": "Stack overflow in nscd due to unbounded alloca use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89092"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-89060",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14357,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "multicluster-observability-addon",
      "cwe": "CWE-551",
      "title": "Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89060"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-11446",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arraytics",
      "product": "Booktics – Appointment Booking Calendar for Service Businesses",
      "cwe": "CWE-862",
      "title": "Booktics – Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11446"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-80469",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.13772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SICK AG",
      "product": "Sentio Creator Extension 'Device Manager'",
      "cwe": "CWE-347",
      "title": "CVE-2026-80469",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80469"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-86815",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.13779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BackWPup",
      "cwe": "CWE-862",
      "title": "BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing Authorization on Job REST Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86815"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-89178",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Howyar",
      "product": "WeenyGenius",
      "cwe": "CWE-940",
      "title": "Howyar｜WeenyGenius - Origin Validation Error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89178"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-14560",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00228,
      "epss_percentile": 0.13467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "teddy-bear-customize-addon",
      "cwe": "CWE-94",
      "title": "Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14560"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-89177",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Howyar",
      "product": "WeenyGenius",
      "cwe": "CWE-757",
      "title": "Howyar｜WeenyGenius - Use of Insecure Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89177"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-18562",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "realmag777",
      "product": "HUSKY – Products Filter for WooCommerce Professional",
      "cwe": "CWE-79",
      "title": "HUSKY <= 1.4.3 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18562"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-78131",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.13288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-401",
      "title": "strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78131"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-84960",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.12841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cbutlerjr",
      "product": "WP-Members Membership Plugin",
      "cwe": "CWE-79",
      "title": "WP-Members Membership Plugin <= 3.5.6 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84960"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-89158",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PCRE",
      "product": "PCRE2",
      "cwe": "CWE-190",
      "title": "PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89158"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-18964",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "premio",
      "product": "Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty",
      "cwe": "CWE-79",
      "title": "Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button <= 3.5.9 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18964"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-89160",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00221,
      "epss_percentile": 0.12637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PCRE",
      "product": "PCRE2",
      "cwe": "CWE-125",
      "title": "PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89160"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-6641",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dglingren",
      "product": "Media Library Assistant",
      "cwe": "CWE-79",
      "title": "Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mla_link_href' Shortcode Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6641"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-6642",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dglingren",
      "product": "Media Library Assistant",
      "cwe": "CWE-79",
      "title": "Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6642"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-78172",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themifyme",
      "product": "Themify – WooCommerce Product Filter",
      "cwe": "CWE-79",
      "title": "Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78172"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-7438",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldthemes",
      "product": "Bold Timeline Lite",
      "cwe": "CWE-79",
      "title": "Bold Timeline Lite <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7438"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-88260",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.09848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainzcompany",
      "product": "Zenius EMS 8.0",
      "cwe": "CWE-288",
      "title": "Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88260"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-78124",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0019,
      "epss_percentile": 0.08718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strongSwan",
      "product": "strongSwan",
      "cwe": "CWE-401",
      "title": "strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78124"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-86782",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Visualizer",
      "cwe": "CWE-639",
      "title": "Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86782"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-73784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise",
      "product": "HPE IceWall products",
      "cwe": "CWE-347",
      "title": "HPE IceWall products, Remote Bypass of Security Restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73784"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-85677",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Gutenverse News",
      "cwe": "CWE-79",
      "title": "Gutenverse News < 3.3.3 - Unauthenticated Stored XSS via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85677"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-86812",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPCafe",
      "cwe": "CWE-284",
      "title": "WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86812"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-14565",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "advanced-customized-prompts",
      "cwe": "CWE-79",
      "title": "Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14565"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-13326",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qt",
      "product": "qt",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13326"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-83545",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CoolClock",
      "cwe": "CWE-79",
      "title": "CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83545"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-83546",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CoolClock",
      "cwe": "CWE-79",
      "title": "CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83546"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-85678",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Builder",
      "cwe": "CWE-79",
      "title": "AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85678"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-86780",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Featured Image with URL",
      "cwe": "CWE-79",
      "title": "Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86780"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2025-15695",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.04679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Translate WordPress with GTranslate",
      "cwe": "CWE-79",
      "title": "GTranslate < 3.0.10 - Admin+ Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15695"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-89151",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.0446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Forgejo",
      "product": "Forgejo",
      "cwe": "CWE-863",
      "title": "Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the \"allow maintainer edit\" feature.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89151"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-14562",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "teddy-bear-customize-addon",
      "cwe": "CWE-200",
      "title": "Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14562"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-14559",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.03384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "teddy-bear-customize-addon",
      "cwe": "CWE-287",
      "title": "Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14559"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-14563",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.03384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "advanced-customized-prompts",
      "cwe": "CWE-287",
      "title": "Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14563"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-82305",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YITH WooCommerce Wishlist",
      "cwe": "CWE-639",
      "title": "YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82305"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-74925",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MultiVendorX",
      "cwe": "CWE-269",
      "title": "MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74925"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-14566",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "advanced-customized-prompts",
      "cwe": "CWE-639",
      "title": "Advanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Metadata Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14566"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-86779",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Visualizer",
      "cwe": "CWE-862",
      "title": "Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86779"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-89145",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00128,
      "epss_percentile": 0.02785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flextype",
      "product": "flextype",
      "cwe": "CWE-79",
      "title": "Flextype CMS 0.9.9 through 1.0.0-alpha.3 Stored XSS via Plugin Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89145"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-88914",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88914"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-86781",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SSL Zen — SSL Certificate Installer & HTTPS Redirects",
      "cwe": "CWE-287",
      "title": "SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86781"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2025-15679",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bull",
      "product": "BullSequana XH3406",
      "cwe": "CWE-258",
      "title": "BMC root account active without password on BullSequana XH3406 and XH3515",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15679"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-89161",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PCRE",
      "product": "PCRE2",
      "cwe": "CWE-590",
      "title": "In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89161"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-89169",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Debian",
      "product": "live-boot",
      "cwe": "CWE-347",
      "title": "live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89169"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-89179",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Howyar",
      "product": "WeenyGenius",
      "cwe": "CWE-353",
      "title": "Howyar｜WeenyGenius - Missing Support for Integrity Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89179"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-89162",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00105,
      "epss_percentile": 0.01178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PCRE",
      "product": "PCRE2",
      "cwe": "CWE-669",
      "title": "In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89162"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-89157",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PCRE",
      "product": "PCRE2",
      "cwe": "CWE-190",
      "title": "PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89157"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-89156",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00102,
      "epss_percentile": 0.01038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PCRE",
      "product": "PCRE2",
      "cwe": "CWE-125",
      "title": "PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89156"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-80462",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Chef Automate",
      "cwe": "CWE-306",
      "title": "Privilege Escalation in Progress Chef Automate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80462"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-82617",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache OpenNLP",
      "cwe": "CWE-1333",
      "title": "Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82617"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-87985",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mistralai",
      "product": "mistral-vibe",
      "cwe": "CWE-184",
      "title": "An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system without approval.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87985"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-87986",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mistralai",
      "product": "mistral-vibe",
      "cwe": "CWE-228",
      "title": "An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87986"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-87987",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mistralai",
      "product": "mistral-vibe",
      "cwe": "CWE-15",
      "title": "An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution without user approval.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87987"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-87988",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mistralai",
      "product": "mistral-vibe",
      "cwe": "CWE-732",
      "title": "An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user approval.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87988"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-53952",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GetSimpleCMS-CE",
      "product": "GetSimpleCMS-CE",
      "cwe": "CWE-285",
      "title": "GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53952"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-62103",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "Everest Forms",
      "cwe": "CWE-502",
      "title": "WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62103"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-62105",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeRex",
      "product": "ThemeREX Addons",
      "cwe": "CWE-502",
      "title": "WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62105"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-71644",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-843",
      "title": "An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71644"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-79395",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-287",
      "title": "An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin username with any arbitrary password when the account's stored password is empty.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79395"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-84390",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiMonitorOnSight",
      "cwe": "CWE-540",
      "title": "A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84390"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-38056",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ST Engineering iDirect",
      "product": "Evolution iQ‑Series terminals",
      "cwe": "CWE-862",
      "title": "ST Engineering iDirect iQ-Series Terminals Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38056"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-54072",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authorizerdev",
      "product": "authorizer",
      "cwe": "CWE-601",
      "title": "Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54072"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-72709",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SPIP",
      "product": "SPIP",
      "cwe": "CWE-862",
      "title": "SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72709"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-72710",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SPIP",
      "product": "SPIP",
      "cwe": "CWE-915",
      "title": "SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72710"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-87984",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mistralai",
      "product": "mistral-vibe",
      "cwe": "CWE-22",
      "title": "An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87984"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-89010",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WAVLINK Technology",
      "product": "WN535M1",
      "cwe": "CWE-78",
      "title": "WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89010"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-89249",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo YPTWallet Stored XSS via CryptoWallet Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89249"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-89253",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo Stored XSS via donationLink in watch page button",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89253"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-89254",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo CustomizeUser Stored XSS via field_name Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89254"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-89255",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo LoginControl Stored XSS via PGP Public Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89255"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-89256",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo Bookmark Plugin Stored XSS via Chapter Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89256"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-89258",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-59",
      "title": "Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89258"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-89259",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-250",
      "title": "Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89259"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-3869",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "Modicon M580",
      "cwe": "CWE-303",
      "title": "CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3869"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-54047",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LaciSynchroni",
      "product": "server",
      "cwe": "CWE-287",
      "title": "Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54047"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-87983",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mistralai",
      "product": "mistral-vibe",
      "cwe": "CWE-22",
      "title": "An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during path validation enables files outside the active workspace to be read without user approval.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87983"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-89212",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perforce",
      "product": "Akana",
      "cwe": "CWE-611",
      "title": "XML External Entity in Akana API Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89212"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-89243",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo Stored XSS via UserGroups setGroup_name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89243"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-90456",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-1392",
      "title": "An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90456"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-62102",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gato GraphQL",
      "product": "Gato GraphQL",
      "cwe": "CWE-266",
      "title": "WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62102"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-62106",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozy Vision Technologies Pvt. Ltd.",
      "product": "SMS Alert Order Notifications",
      "cwe": "CWE-266",
      "title": "WordPress SMS Alert Order Notifications plugin <= 3.9.9 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62106"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-62107",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masteriyo",
      "product": "Masteriyo - LMS",
      "cwe": "CWE-502",
      "title": "WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62107"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-71416",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "headroomlabs-ai",
      "product": "headroom",
      "cwe": "CWE-287",
      "title": "Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71416"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-78224",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NextGen Healthcare",
      "product": "Mirth Connect",
      "cwe": "CWE-611",
      "title": "NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78224"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-89009",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WAVLINK Technology",
      "product": "WN535M1",
      "cwe": "CWE-36",
      "title": "WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89009"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-89266",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nothings",
      "product": "stb_vorbis",
      "cwe": "CWE-787",
      "title": "stb_vorbis through 1.22 heap buffer overflow via codebook multiplicands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89266"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-44715",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openmrs",
      "product": "org.openmrs.module:legacyui-api",
      "cwe": "CWE-285",
      "title": "OpenMRS has Broken Access Control in HL7 Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44715"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-72708",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SPIP",
      "product": "SPIP",
      "cwe": "CWE-89",
      "title": "SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72708"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-82578",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NextGen Healthcare",
      "product": "Mirth Connect",
      "cwe": "CWE-611",
      "title": "NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82578"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-89013",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "Dolibarr",
      "cwe": "CWE-863",
      "title": "Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89013"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-89146",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libp2p",
      "product": "libp2p-rendezvous",
      "cwe": "CWE-190",
      "title": "libp2p-rendezvous through 0.17.1 Denial of Service via Unbounded Registration TTL in Discovery Responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89146"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-89147",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "net-snmp",
      "product": "Net-SNMP",
      "cwe": "CWE-400",
      "title": "Net-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89147"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-89250",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-306",
      "title": "WWBN AVideo Unauthenticated File Read via getRecordedFile.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89250"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-89260",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moxi624",
      "product": "MoguBlog",
      "cwe": "CWE-611",
      "title": "MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89260"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-89262",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moxi624",
      "product": "MoguBlog",
      "cwe": "CWE-639",
      "title": "MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89262"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-90444",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-78",
      "title": "A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90444"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-38058",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ST Engineering iDirect",
      "product": "Evolution iQ‑Series terminals",
      "cwe": "CWE-497",
      "title": "ST Engineering iDirect iQ-Series Terminals Exposure of Sensitive System Information to an Unauthorized Control Sphere",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38058"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-85979",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perforce Software",
      "product": "Puppet Enterprise",
      "cwe": "CWE-20",
      "title": "Command Injection in Puppet Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85979"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-70341",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-416",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70341"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-7863",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
      "product": "Pardus Software",
      "cwe": "CWE-78",
      "title": "OS Command Injection in TUBITAK BILGEM's Pardus Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7863"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-89066",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "projen",
      "cwe": "CWE-78",
      "title": "OS command injection in the task synthesis component in projen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89066"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-54174",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chainguard-dev",
      "product": "melange",
      "cwe": "CWE-345",
      "title": "melange: Incomplete package integrity verification allows data section substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54174"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-89090",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS SDK for Go v2",
      "cwe": "CWE-248",
      "title": "Denial of service in the event stream header decoder in AWS SDK for Go v2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89090"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-90451",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-1392",
      "title": "An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90451"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-49464",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nl-portal",
      "product": "nl-portal-backend-libraries",
      "cwe": "CWE-639",
      "title": "NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49464"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-8301",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
      "product": "Pardus Boot Repair",
      "cwe": "CWE-78",
      "title": "OS Command Injection in TUBITAK BILGEM's Pardus-boot-repair",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8301"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-8303",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
      "product": "Pardus-software",
      "cwe": "CWE-266",
      "title": "Privilege Escalation in TUBITAK BILGEM's Pardus-software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8303"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-89099",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-362",
      "title": "Race Condition in MongoDB Server Document Value Layer Leads to Memory Corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89099"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-62109",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wowDevs",
      "product": "Sky Addons for Elementor",
      "cwe": "CWE-89",
      "title": "WordPress Sky Addons for Elementor plugin <= 3.8.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62109"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-62112",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melograno Venture Studio",
      "product": "Amelia",
      "cwe": "CWE-89",
      "title": "WordPress Amelia plugin <= 2.4.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62112"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-90460",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Keystone",
      "cwe": "CWE-863",
      "title": "An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH /v3/credentials does not validate the requested post-update project_id, allowing any delegated token to move a credential to an unauthorized project. All Keystone deployments using delegated authentication are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90460"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-49846",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "libks",
      "cwe": "CWE-22",
      "title": "libks has path traversal in kws HTTP parser via URI segment overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49846"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-50013",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SpectoLabs",
      "product": "hoverfly",
      "cwe": "CWE-362",
      "title": "Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50013"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-54135",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SimulPiscator",
      "product": "AirSane",
      "cwe": "CWE-400",
      "title": "AirSane has a Remote Denial of Service (OOM) via Unvalidated Content-Length in HTTP Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54135"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-68497",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-400",
      "title": "jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68497"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-79393",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79393"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-87776",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "compression",
      "product": "compression",
      "cwe": "CWE-401",
      "title": "compression vulnerable to Denial of Service via memory leak on premature response close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87776"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-54240",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libde265",
      "cwe": "CWE-190",
      "title": "libde265: Pixel accessor signed integer overflow causes heap OOB read/write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54240"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-54241",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libde265",
      "cwe": "CWE-122",
      "title": "libde265: SAO sequential filter heap buffer overflow via signed integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54241"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-57842",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The NetBSD Foundation",
      "product": "NetBSD",
      "cwe": "CWE-415",
      "title": "NetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57842"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-47773",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arduino-libraries",
      "product": "ArduinoBLE",
      "cwe": "CWE-131",
      "title": "ArduinoBLE: Memory corruption via malformed ATT write request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47773"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-82583",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NextGen Healthcare",
      "product": "Mirth Connect",
      "cwe": "CWE-89",
      "title": "NextGen Healthcare Mirth Connect SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82583"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-87020",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Orthanc",
      "product": "DICOM Server",
      "cwe": "CWE-190",
      "title": "Orthanc DICOM Server Integer Overflow or Wraparound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87020"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-54166",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shelf-nu",
      "product": "shelf.nu",
      "cwe": "CWE-918",
      "title": "Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54166"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-62089",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pixar Labs",
      "product": "Master Addons for Elementor",
      "cwe": "CWE-862",
      "title": "WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62089"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-78807",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-346",
      "title": "An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78807"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-89012",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "Dolibarr",
      "cwe": "CWE-178",
      "title": "Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89012"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-89245",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "WWBN AVideo Cross-Site Request Forgery via playlistRemove.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89245"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-89251",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-345",
      "title": "AVideo Missing Authorization via AD_Server log.php Wallet Credit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89251"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-89252",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-639",
      "title": "AVideo Missing Authorization in addLiveLink.php LiveLink Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89252"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-90445",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-22",
      "title": "An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system's stored data or tamper with application configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90445"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-90447",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-290",
      "title": "A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-based authorization check and reach the alternate path's fixed, elevated role instead. This allows a low-privileged authenticated attacker who knows the shared credential to perform actions reserved for a higher-privileged role.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90447"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-90448",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-862",
      "title": "A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an attacker-chosen identifier, using the application's own elevated backend credentials. This allows an authenticated user on a deployment intended to be read-only to forge or overwrite stored records that should not be modifiable in that deployment mode.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90448"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-85083",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CareCam",
      "product": "ANJIA AJL33PC0801 Firmware",
      "cwe": "CWE-798",
      "title": "CareCam Pro IP Cameras Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85083"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-45056",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "matrix-org",
      "product": "matrix-rust-sdk",
      "cwe": "CWE-290",
      "title": "Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45056"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-48490",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arduino",
      "product": "ArduinoCore-avr",
      "cwe": "CWE-120",
      "title": "ArduinoCore-AVR: Stack-Based Buffer Overflow in String float/double concatenation handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48490"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-50025",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "t-mart",
      "product": "mousehole",
      "cwe": "CWE-200",
      "title": "Mousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50025"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-89242",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-918",
      "title": "WWBN AVideo Unauthenticated SSRF via login.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89242"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-89248",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "AVideo WebRTC Plugin Information Disclosure via status.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89248"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-89261",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moxi624",
      "product": "MoguBlog",
      "cwe": "CWE-306",
      "title": "MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89261"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-89263",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moxi624",
      "product": "MoguBlog",
      "cwe": "CWE-306",
      "title": "MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89263"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-90449",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-306",
      "title": "When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative interface, which manages the credential store used to gate every other service in the deployment, is delegated entirely to that third-party interface's own login mechanism. Any authentication weakness in that bundled interface would compromise the credential store protecting the rest of the deployment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90449"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-90457",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-916",
      "title": "The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a separate, stronger hashing algorithm used for the same password on another authentication path. A party able to read this file, including a local user or a party with access to a configuration backup, could feasibly recover the underlying password through offline computation, compromising the administrative credential across every path that accepts it.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90457"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-15710",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netskope",
      "product": "Endpoint DLP",
      "cwe": "CWE-908",
      "title": "Netskope Client Endpoint DLP Kernel Driver Information Leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15710"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-57843",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The NetBSD Foundation",
      "product": "NetBSD",
      "cwe": "CWE-732",
      "title": "NetBSD mm_open() PK_KMEM Flag Kernel Pointer Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57843"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-89065",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "projen",
      "cwe": "CWE-23",
      "title": "Relative path traversal in the generated file manifest cleanup component in projen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89065"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-89332",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Kiro IDE",
      "cwe": "CWE-201",
      "title": "Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89332"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-15439",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rubengc",
      "product": "GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI",
      "cwe": "CWE-89",
      "title": "GamiPress <= 7.9.7 - Authenticated (Subscriber+) SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15439"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-49463",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nl-portal",
      "product": "nl.nl-portal:besluiten",
      "cwe": "CWE-200",
      "title": "NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49463"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-50018",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SpectoLabs",
      "product": "hoverfly",
      "cwe": "CWE-400",
      "title": "Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50018"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-54248",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kimdre",
      "product": "doco-cd",
      "cwe": "CWE-347",
      "title": "Doco-CD has an OCI Trust Policy Bypass via Artifact-Contained Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54248"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-54258",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZoneMinder",
      "product": "zoneminder",
      "cwe": "CWE-639",
      "title": "Cross-monitor event media authorization bypass in direct event media endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54258"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-62110",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldthemes",
      "product": "Bold Page Builder",
      "cwe": "CWE-79",
      "title": "WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62110"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-62111",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ido Kobelkowsky",
      "product": "Simple Payment",
      "cwe": "CWE-79",
      "title": "WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62111"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-62138",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Visual Composer",
      "product": "Visual Composer Website Builder",
      "cwe": "CWE-79",
      "title": "WordPress Visual Composer Website Builder plugin <= 45.16.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62138"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-85116",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple CAPTCHA with Cloudflare Turnstile",
      "cwe": "CWE-74",
      "title": "Simple CAPTCHA with Cloudflare Turnstile 1.2.2 - 1.42.1 - Unauthenticated Arbitrary Shortcode Execution via Contact Form 7 Field Repopulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85116"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-54165",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smgdkngt",
      "product": "dobase",
      "cwe": "CWE-79",
      "title": "Stored DOM-XSS in public shared-folder image gallery (one-click, unauthenticated victim)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54165"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-49992",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kimai",
      "product": "kimai",
      "cwe": "CWE-352",
      "title": "Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49992"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-90455",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-1395",
      "title": "A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90455"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-90461",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-923",
      "title": "OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90461"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-48496",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-profiler",
      "cwe": "CWE-770",
      "title": "opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48496"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-89329",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-1322",
      "title": "Device-mapper-multipath: local denial of service via blocking ipc send operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89329"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-7298",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IdeaSoft Software Industry and Trade Inc.",
      "product": "Smart E-Commerce",
      "cwe": "CWE-79",
      "title": "Reflected XSS in IdeaSoft's Smart E-Commerce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7298"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-18495",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-122",
      "title": "Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18495"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-77490",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-79",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77490"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-81907",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Express delete_entries allowing mass deletion of all entity records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81907"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-18061",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS Advanced JDBC Wrapper",
      "cwe": "CWE-611",
      "title": "Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18061"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-18122",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18122"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-68528",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68528"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-81908",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81908"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-90452",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-295",
      "title": "Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90452"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-81861",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "SCADAPack 47x",
      "cwe": "CWE-522",
      "title": "CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81861"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-81909",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81909"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-81910",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-1336",
      "title": "Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81910"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-82215",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payment Gateway PayPay for WooCommerce",
      "cwe": "CWE-345",
      "title": "WC PayPay Gateway 0.5 - 0.9.3 - Unauthenticated Payment Bypass via Unverified Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82215"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-81911",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81911"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-81912",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81912"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-87910",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-22",
      "title": "tarfile hardlink fallback ignores custom extraction filter rejection via None",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87910"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-8304",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
      "product": "Pardus About",
      "cwe": "CWE-862",
      "title": "Information Disclosure in TUBITAK BILGEM's Pardus About",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8304"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-77159",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-61",
      "title": "Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership change via symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77159"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-62133",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rometheme",
      "product": "RTMKit",
      "cwe": "CWE-352",
      "title": "WordPress RTMKit plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62133"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-27378",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Deposits and Partial Payments for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Deposits and Partial Payments for WooCommerce plugin <= 3.1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27378"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-49462",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nl-portal",
      "product": "nl.nl-portal:app",
      "cwe": "CWE-200",
      "title": "nl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49462"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-49865",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kimai",
      "product": "kimai",
      "cwe": "CWE-918",
      "title": "Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49865"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-62088",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10up",
      "product": "ElasticPress",
      "cwe": "CWE-201",
      "title": "WordPress ElasticPress plugin <= 5.3.4 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62088"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-62114",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Passster",
      "cwe": "CWE-862",
      "title": "WordPress Passster plugin <= 4.3.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62114"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-62132",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masteriyo",
      "product": "Masteriyo - LMS",
      "cwe": "CWE-862",
      "title": "WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62132"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-62135",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "Booktics",
      "cwe": "CWE-862",
      "title": "WordPress Booktics plugin <= 1.0.24 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62135"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-62136",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdesk",
      "product": "Flexible Quantity – Measurement Price Calculator for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62136"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-62137",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "John James Jacoby",
      "product": "bbPress",
      "cwe": "CWE-862",
      "title": "WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62137"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-62140",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ExpressTech Systems",
      "product": "Quiz And Survey Master",
      "cwe": "CWE-639",
      "title": "WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62140"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-68526",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68526"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-81913",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-601",
      "title": "Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81913"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-82213",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Nexi XPay Build",
      "cwe": "CWE-639",
      "title": "Nexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Saved Payment Token Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82213"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-82535",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chamilo",
      "product": "chamilo-lms",
      "cwe": "CWE-79",
      "title": "Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82535"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-86809",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Persian Elementor",
      "cwe": "CWE-345",
      "title": "Persian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authority Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86809"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-89239",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo Reflected XSS via Referer Header Comment Breakout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89239"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-89240",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo Reflected XSS via confirmLivePassword.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89240"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-89241",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo Reflected XSS via confirmLivePassword.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89241"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-89244",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo Reflected XSS via Gallery Category getBackURL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89244"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-89247",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-91",
      "title": "WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89247"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-89257",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-639",
      "title": "AVideo through 29.0 Cross-User Category Asset Deletion via Missing Ownership Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89257"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-89264",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moxi624",
      "product": "MoguBlog",
      "cwe": "CWE-639",
      "title": "MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89264"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-89265",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moxi624",
      "product": "MoguBlog",
      "cwe": "CWE-862",
      "title": "MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89265"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-90443",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-79",
      "title": "A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90443"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-90446",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-918",
      "title": "An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an arbitrary backend path, causing the application's own elevated service credentials to be used against unintended internal endpoints. This could allow an attacker to enumerate or read internal configuration and administrative data from the backend data store that would otherwise be restricted.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90446"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-90450",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-863",
      "title": "The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authenticated user regardless of their assigned role, and any newly added handler is fail-open by default until explicitly added to the table.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90450"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-90454",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-862",
      "title": "A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated user on a deployment intended to be read-only to add or remove tags on stored session records.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90454"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-68535",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68535"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-81915",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-639",
      "title": "In Concrete CMS below 9.5.3, Page Type update omits object-level authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81915"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-81916",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-639",
      "title": "Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81916"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-81917",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81917"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-89148",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "AVideo Open Redirect via playlistSort.php Referer Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89148"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-89246",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-1236",
      "title": "WWBN AVideo CSV Formula Injection via myComments.download.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89246"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-90453",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISA",
      "product": "Malcolm",
      "cwe": "CWE-601",
      "title": "A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90453"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-45057",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "matrix-org",
      "product": "matrix-sdk-ui",
      "cwe": "CWE-345",
      "title": "matrix-sdk-ui: Incomplete edit validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45057"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-89298",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-200",
      "title": "Keycloak-services: keycloak-services: confidential client secret disclosed to view-clients role via client registration get",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89298"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-78546",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Citirx",
      "product": "Workspace app for Windows",
      "cwe": "CWE-125",
      "title": "Out-of-Bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78546"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-81918",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81918"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-86813",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MetForm",
      "cwe": "CWE-93",
      "title": "MetForm < 4.1.9 - Unauthenticated Email Header Injection via Notification Reply-To",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86813"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-78547",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Citrix",
      "product": "Citrix Workspace app for Windows",
      "cwe": "CWE-787",
      "title": "Out-of-Bounds Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78547"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2024-12145",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "buddypress",
      "product": "BuddyPress",
      "cwe": "CWE-862",
      "title": "BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-12145"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-9160",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arma Digital Media Inc.",
      "product": "Website Template",
      "cwe": "CWE-1336",
      "title": "CSTI in Arma Digital's Website Template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9160"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-49439",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openremote",
      "product": "openremote",
      "cwe": "CWE-862",
      "title": "OpenRemote read-only asset users can write predicted datapoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49439"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-62113",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anh Tran",
      "product": "Slim SEO",
      "cwe": "CWE-639",
      "title": "WordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62113"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-62134",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "Starter Templates",
      "cwe": "CWE-639",
      "title": "WordPress Starter Templates plugin <= 4.7.5 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62134"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-62139",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Site Kit by Google",
      "cwe": "CWE-352",
      "title": "WordPress Site Kit by Google plugin <= 1.186.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62139"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-11765",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
      "product": "Pardus Pen",
      "cwe": "CWE-88",
      "title": "Argument Injection in TUBITAK BILGEM's Pardus Pen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11765"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2025-69904",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69904"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-52630",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52630"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-67211",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache OpenNLP",
      "cwe": "CWE-789",
      "title": "Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67211"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-71641",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergency recovery logic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71641"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-71646",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() in swarm_exploration/exploration_manager/src/fast_exploration_fsm.cpp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71646"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-79035",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79035"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-79362",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79362"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-79394",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79394"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-79396",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79396"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-80926",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix use-after-free in oplock break notification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80926"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-80927",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80927"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-80928",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smack: fix cred UAF in smack_file_send_sigiotask()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80928"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-80929",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sysctl: move the \"cad_pid\" entry from pid_table[] to kern_reboot_table[]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80929"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-80930",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80930"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-80931",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "w1: ds28e17: reject an oversize length on an I2C block read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80931"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-80932",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vsock/virtio: flush works in dependency order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80932"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-80933",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: validate default EEPROM firmware size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80933"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-80934",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80934"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-80935",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80935"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-80936",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7925: cancel mlo_pm_work on stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80936"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-80937",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80937"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-80938",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80938"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-80939",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80939"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-80940",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtw88: pci: fix resource leak on failed NAPI setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80940"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-80941",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80941"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-80942",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80942"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-80943",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80943"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-80944",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mwifiex: Detach sync cmd buffer on interrupted wait",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80944"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-80945",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: iaa - unmap dst before software fallback on decompress",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80945"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-80946",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: copy request headers via a stack buffer for io-uring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80946"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-80947",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80947"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-80948",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80948"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-80949",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80949"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-80950",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: renesas: Check that the transfer is valid before accessing it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80950"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-80951",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: master: svc: bound IBI payload to the requested max_payload_len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80951"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-80952",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: master: Fix info leak and UAF in device unregister path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80952"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-80953",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: master: adi: initialize the lock before enabling interrupts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80953"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-80954",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80954"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-80955",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: fix use-after-free and invalid seg operations in kset_replay()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80955"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-80956",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: only hand out initialized cache segments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80956"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-80957",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: detect a cycle in the last-kset chain during replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80957"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-80958",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: clamp the tail kset read to the segment data region",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80958"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-80959",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: bound the persisted tail-position offset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80959"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-80960",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: validate on-media seg_num against the cache device size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80960"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-80961",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: validate kset key_num and intra-segment bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80961"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-80962",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: validate geometry fields from on-disk cache_info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80962"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-80963",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-stats: fix a crash if allocation of per-cpu data fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80963"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-80964",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: virmidi: Check card index validity at probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80964"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-80965",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: serial-u16550: Check card index validity at probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80965"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-80966",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: portman2x4: Check card index validity at probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80966"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-80967",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: pcxhr: initialize mutexes before requesting threaded IRQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80967"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-80968",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: mts64: Check card index validity at probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80968"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-80969",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: mpu401: Check card index validity at probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80969"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-80970",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: FCP: do not copy out an uninitialised init response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80970"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-80971",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: bcd2000: clear the URB pointers on disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80971"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-80972",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: aloop: Check card index validity at probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80972"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-80973",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: 6fire: bound the MIDI event length from the device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80973"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-80974",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mfd: sm501: Fix potential memory leaks during remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80974"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-80975",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mfd: qnap-mcu: keep the reply buffer alive past a command timeout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80975"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-80976",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "seg6: reset IP6CB after IPv6 decapsulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80976"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-80977",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: skbuff: don't touch shared zerocopy state in skb_tx_error()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80977"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-80978",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: cap advertised IP tunnel headroom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80978"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-80979",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: unregister the connection before draining the rx tasklet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80979"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-80980",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: stop killed, freed and out_of_sync sharing a byte",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80980"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-80981",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80981"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-80982",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: fix use-after-free in smc_rx_pipe_buf_release()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80982"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-80983",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: fix socket refcount leak in smc_switch_conns()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80983"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-80984",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: do not dereference an unset send buffer on the SMC-D teardown path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80984"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-80985",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80985"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-80986",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80986"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-80987",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NTB: ntb_transport: Reject oversized TX buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80987"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-80988",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NTB: ntb_transport: Fail TX enqueue when the QP link is down",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80988"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-80989",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: thunderbolt: Mark the connection down when bringing it up fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80989"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-80990",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: thunderbolt: Release the Rx HopID that was handed out on mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80990"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-80991",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ravb: serialize PTP clock teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80991"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-80992",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ravb: avoid dereferencing an invalid PTP clock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80992"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-80993",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: phylink: correctly validate returned PCS in phylink_inband_caps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80993"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-80994",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: openvswitch: fix flow mask use-after-free on flow deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80994"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-80995",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mctp: hold a reference to the route device in mctp_route_lookup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80995"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-80996",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: l2tp: do not propagate multicast notification errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80996"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-80997",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ipa: fix stalled modem TX queue after runtime resume",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80997"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-80998",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bnxt: ring the doorbell when SW USO exits early",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80998"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-80999",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80999"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-81000",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: tun: bound receive headroom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81000"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-81001",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "slip: fix use-after-free in sl_sync()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81001"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-81002",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xdp: fix zero-copy frame layout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81002"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-81003",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/iucv: filter frames in afiucv_hs_rcv() by ingress device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81003"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-81004",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmi:msghandler: Cancel work cleanly on an error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81004"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-81005",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmi: si: Fix NULL pointer dereference after failed registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81005"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-81006",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmi: Remove all sysfs files on registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81006"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-81007",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmi: ipmb: validate write message length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81007"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-81008",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "interconnect: Fix use after free in icc_get() and of_icc_get_by_index()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81008"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-81009",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/query: cap user size passed to copy_struct_to_user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81009"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-81010",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/waitid: honor task_work cancellation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81010"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-81011",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: hp-bioscfg: pass validated element count to package parsers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81011"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-81012",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81012"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-81013",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: hp-bioscfg: fix heap OOB read on empty password write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81013"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-81014",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81014"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-81015",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81015"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-81016",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86/amd/pmc: Propagate SMU errors and validate S2D address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81016"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-81017",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/chrome: sensorhub: Bound the EC-reported sensor number",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81017"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-81018",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: think-lmi: Free system certificate signatures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81018"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-86793",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": null,
      "title": "CVE-2026-86793",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86793"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-89436",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89436"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-89437",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: int1092: Fix potential memory leak in sar_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89437"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-89438",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: ISST: Validate logical CPU id and clos id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89438"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-89439",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: ISST: Add a NULL check for sst_inst[]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89439"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-89440",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: via-sdmmc: stop card-detect handling on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89440"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-89441",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: via-sdmmc: cancel card-detect work on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89441"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-89442",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: ISST: Validate socket ID in clos_assoc ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89442"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-89443",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: ISST: Validate level in perf mask ioctls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89443"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-89444",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89444"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-89445",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommufd: Fix UAF in selftest IOPF reporting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89445"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-89446",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommufd: Release current IOAS on xa_store() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89446"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-89447",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommufd: Avoid locking internal accesses during unmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89447"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-89448",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/vt-d: Force requesting ACS when tboot is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89448"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-89449",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89449"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-89450",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89450"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-89451",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/sva: Set handle->dev before the SVA handle is visible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89451"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-89452",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/msm: Unwind probe state on registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89452"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-89453",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/amd: Put PCI device after handling PPR faults",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89453"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-89454",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89454"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-89455",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: plda: Fix use-after-free of event IRQs during teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89455"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-89456",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/dasd: Propagate partial completion length across ERP recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89456"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-89457",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/dasd: Guard sysfs discipline callbacks against unallocated private data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89457"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-89458",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/dasd: Do not complete a failed ESE read as successful",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89458"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-89459",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/percpu: Fix MVIY_PERCPU() with older binutils",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89459"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-89460",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89460"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-89461",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: max17040: synchronize work cancellation on suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89461"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-89462",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: max17040: propagate register read errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89462"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-89463",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: ucs1002: fix use-after-free on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89463"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-89464",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: twl4030_charger: cancel workers via devm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89464"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-89465",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: rt9455: quiesce delayed work before teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89465"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-89466",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: qcom_battmgr: terminate the strings from firmware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89466"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-89467",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: qcom_battmgr: fix use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89467"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-89468",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: lp8788-charger: fix use-after-free on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89468"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-89469",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: lp8727: fix use-after-free in lp8727_release_irq()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89469"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-89470",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89470"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-89471",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: cros_usbpd-charger: bound the EC-reported port count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89471"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-89472",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: charger-manager: register regulators before exposing sysfs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89472"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-89473",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: bq25890: Fix power_supply reference leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89473"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-89474",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: bq256xx: drain usb_work before freeing the charger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89474"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-89475",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: bq24257: fix use-after-free on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89475"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-89476",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: fix stream->outcnt underflow on duplicate RECONF responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89476"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-89477",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: fix NULL deref on untransmitted RECONF completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89477"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-89478",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: drop a chunk if its transport was removed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89478"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-89479",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: stop processing a packet once its association is deleted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89479"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-89480",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-tcp: reject a read that transferred too few bytes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89480"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-89481",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-tcp: fix host memory disclosure on R2T for a read command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89481"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-89482",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89482"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-89483",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme: zero the discard fallback page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89483"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-89484",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "lockd: fix NULL dereference on lockowner allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89484"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-89485",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "lockd: pin next file across nlm_inspect_file lock-drop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89485"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-89486",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89486"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-89487",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "openvswitch: only skb_tx_error() a packet we are about to drop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89487"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-89488",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "openvswitch: Fix CT limit teardown use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89488"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-89489",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "openrisc: fix arbitrary kernel memory access via or1k_atomic syscall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89489"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-89490",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: fix readdir position truncation on 32-bit kernels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89490"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-89491",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89491"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-89492",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: validate directory-index entry counts when reading metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89492"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-89493",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: validate rl_used against rl_count in refcount block validator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89493"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-89494",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: validate lengths in dlm_mig_lockres_handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89494"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-89495",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: bound namelen in dlm_migrate_request_handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89495"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-89496",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: always run deallocs on copy-on-write completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89496"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-89497",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "orangefs: skip leading spaces before parsing client debug masks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89497"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-89498",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "orangefs: fix double-free of trailer_buf on readdir copy failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89498"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-89499",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Stop remote reader update when page swap fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89499"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-89500",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89500"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-89501",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Hold cpu_buffer::lock when resizing a subbuf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89501"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-89502",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Free cpu_buffer::free_page with subbuf_order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89502"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-89503",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89503"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-89504",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89504"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-89505",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/uverbs: Guard legacy bundles without method_elm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89505"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-89506",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89506"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-89507",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/ucma: Lock the handler in ucma_write_cm_event()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89507"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-89508",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/ucma: Lock the handler in ucma_set_ib_path()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89508"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-89509",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/ionic: Embed counter driver data in rdma_counter allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89509"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-89510",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/cxgb4: Cancel reg_work before freeing device on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89510"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-89511",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "qede: Fix NULL pointer dereference in TPA fragment processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89511"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-89512",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "remoteproc: scp: Fix device reference leak on failed lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89512"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-89513",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RISC-V: KVM: Fix PMU event info array size overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89513"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-89514",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89514"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-89515",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89515"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-89516",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89516"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-89517",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Fix rq->core_pick corruption under core scheduling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89517"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-89518",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Fix this_rq() assumptions in dispatch kfuncs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89518"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-89519",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89519"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-89520",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched/core: Make core-sched flips wait for in-flight selections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89520"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-89521",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched/core: Handle pick_task() releasing the rq lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89521"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-89522",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: staging/ipu7: fix async notifier UAF on probe error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89522"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-89523",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7925: cancel pending mlo_pm_work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89523"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-89524",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89524"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-89525",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "udf: reject VAT indexes equal to the entry count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89525"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-89526",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Validate Read chunk positions before reconstruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89526"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-89527",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Use svc_xprt_put to free listener on create failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89527"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-89528",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Reject Read lists that exceed the page budget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89528"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-89529",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Reject oversized Read segments at decode time",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89529"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-89530",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Reject inline replies that overflow the pull-up buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89530"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-89531",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Reject connection when transport allocation fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89531"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-89532",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Fix pcl_for_each_segment for empty chunks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89532"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-89533",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Fix offset arithmetic in read_chunk_range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89533"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-89534",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89534"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-89535",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89535"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-89536",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: wait for in-flight client TLS handshake callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89536"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-89537",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89537"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-89538",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89538"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-89539",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: reject duplicate CREDS_VALUE options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89539"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-89540",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sunrpc: init gssp_lock before publishing proc entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89540"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-89541",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: harden gss_unwrap_resp_priv length checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89541"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-89542",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: harden gss_krb5_unwrap_v2 against short tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89542"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-89543",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89543"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-89544",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: fix gssx_dec_option_array error path bugs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89544"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-89545",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sunrpc: defer rq_argp and rq_resp free until after RCU grace period",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89545"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-89546",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: close backchannel before destroying callback service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89546"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-89547",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: Check svc pool percpu counter allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89547"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-89548",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: always drain cache_cleaner before destroying a cache_detail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89548"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-89549",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sunrpc: route to a populated pool in svc_pool_for_cpu()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89549"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-89550",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: svcauth_gss: enforce krb5 token minimum length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89550"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-89551",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89551"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-89552",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "params: fix charp corruption on allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89552"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-89553",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nouveau/gem: reserve the bo in the info ioctl around the vma lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89553"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-89554",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89554"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-89555",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mpls: reload header after pskb_may_pull()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89555"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-89556",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "module: validate string table section types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89556"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-89557",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md: do overflow check for sb->bblog_shift in super_1_load()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89557"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-89558",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/raid10: fix still_degraded being inverted in raid10_sync_request()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89558"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-89559",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libnvdimm/labels: Prevent integer overflow in __nd_label_validate()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89559"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-89560",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89560"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-89561",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89561"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-89562",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ip6_gre: fix hardware header length for NBMA tunnels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89562"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-89563",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89563"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-89564",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ip: orphan prefetched skbs before multicast forwarding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89564"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-89565",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipip: fix skb leak in collect_md mode when metadata_dst allocation fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89565"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-89566",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "jbd2: check need_resched() when skipping busy checkpoint buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89566"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-89567",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "jbd2: bound shrinker scans by examined checkpoint buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89567"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-89568",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "kho: fix size calculation in kho_preserved_memory_reserve()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89568"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-89569",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: RFCOMM: serialize security confirmation handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89569"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-89570",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/mce: Make the MCE notifier per-region",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89570"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-89571",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/features: bound fwctl command payload to the input buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89571"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-89572",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq: apple-soc: Fix OPP table cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89572"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-89573",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm array: reject an array block whose value size is not the caller's",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89573"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-89574",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm array: validate array block headers on read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89574"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-89575",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm raid1: reserve space for NUL-terminator in build_constructor_string()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89575"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-89576",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-era: fix shadowed superblock leak on take-snap failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89576"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-89577",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-io: report non-retryable errors separatedly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89577"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-89578",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-io: clone the source bio instead of copying its biovec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89578"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-89579",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Harden bloom filter sizing and indexing on 32-bit kernels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89579"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-89580",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Disable preemption in __bpf_get_stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89580"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-89581",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, x86: Fix per-CPU address resolution into an extended register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89581"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-89582",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bnx2x: fix double free in bnx2x_init_firmware() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89582"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-89583",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: eir: Fix OOB read in eir_get_service_data()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89583"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-89584",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "block: validate user space vectors during extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89584"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-89585",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "auxdisplay: charlcd: cancel backlight work on registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89585"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-89586",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89586"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-89587",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: pfr_update: fix stack buffer overflow in query_capability()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89587"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-89588",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: APEI: GHES: fix ARM section length accounting after header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89588"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-89589",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89589"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-89590",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/rocket: Fix error path handling in rocket_job_run()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89590"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-89591",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/rocket: initialize job domain before cleanup paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89591"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-89592",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89592"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-89593",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hugetlb: only adjust reservation during unmapping if mapcount is 0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89593"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-89594",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89594"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-89595",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fsnotify: Fix stale object mask after concurrent mark updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89595"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-89596",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "forcedeth: fix off-by-one when saving/restoring non-PCI config space",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89596"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-89597",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: uvesafb: unregister connector callback on init failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89597"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-89598",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: ssd1307fb: defer I2C transfers from damage callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89598"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-89599",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: omapfb: panel-dsi-cm: initialize lock before registering display",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89599"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-89600",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fanotify: fix use-after-free of file range info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89600"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-89601",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext2: Fix lost inode updates for IS_SYNC inodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89601"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-89602",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: skip sufficiently large global buffers when resizing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89602"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-89603",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "entry: Fix seccomp bypass after ptrace with TSYNC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89603"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-89604",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "efivarfs: Rate limit statfs() handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89604"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-89605",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ecryptfs: release message context on send failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89605"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-89606",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ecryptfs: reject too-small tag 70 packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89606"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-89607",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89607"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-89608",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ecryptfs: pass packet set buffer size to parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89608"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-89609",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ecryptfs: hold msg ctx list lock when cleaning daemon queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89609"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-89610",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: verify run length exceeding volume boundary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89610"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-89611",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: validate non-resident attribute offsets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89611"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-89612",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: reject invalid MFT LCNs from boot sector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89612"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-89613",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: reject invalid empty mapping pairs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89613"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-89614",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: bound the free-cluster bitmap scan to the volume",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89614"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-89615",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: bound page_lcns[] index by the log record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89615"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-89616",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89616"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-89617",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: validate dirty page table on log replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89617"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-89618",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "eventfs: Initialize ei->children and ei->list in init_ei()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89618"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-89619",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89619"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-89620",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: intel-thc-hid: intel-quickspi: validate report size before copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89620"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-89621",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: mcp2221: validate report size in mcp2221_raw_event()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89621"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-89622",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89622"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-89623",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: mcp2221: stop device IO before hid_hw_stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89623"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-89624",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: universal-pidff: stop the device when force-feedback init fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89624"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-89625",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89625"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-89626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: sensor: custom: Fix field sysfs group cleanup on failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89626"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-89627",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: roccat: free buffered reports when destroying device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89627"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-89628",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: picolcd: clamp eeprom debugfs read to bytes actually received",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89628"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-89629",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: corsair-void: Check size of status and firmware events before reading them",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89629"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-89630",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: restore the data_offset bound in is_valid_oplock_break()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89630"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-89631",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: reject a tree connect response whose byte count is too small",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89631"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-89632",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89632"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-89633",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89633"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-89634",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix ALIGN() overflow in symlink_data() error context loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89634"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-89635",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: only rebind the reopened file's own oplock on durable reconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89635"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-89636",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: clear ce->tgthint in free_tgts()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89636"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-89637",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89637"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-89638",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89638"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-89639",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89639"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-89640",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89640"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-89641",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89641"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-89642",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cifs: call pagecache_isize_extended() in cifs_setsize() when extending",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89642"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-89643",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "audit: avoid dropping live tree ref on fsnotify rule autoremove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89643"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-89644",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix extent map leak in NOCOW direct I/O write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89644"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-89645",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: drop recovered reloc root refs on recovery failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89645"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-89646",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: fix leaked inode reference on writeback abort at umount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89646"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-89647",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: do not repeat ceph_trim_dentries() if no progress possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89647"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-89648",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: cap delegated inode count in ceph_parse_deleg_inos()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89648"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-89649",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: bound xattr value length in __build_xattrs()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89649"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-89650",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: bound num_export_targets array for mds info v2/v3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89650"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-89651",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: bound MDSCapAuth path and fs_name decode in handle_session()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89651"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-89652",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: bound copied dentry name length in NFS export get_name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89652"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-89653",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89653"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-89654",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: fix UAF in check_new_map() on session freed during unlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89654"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-89655",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89655"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-89656",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: reject buckets with mismatched CRUSH ids",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89656"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-89657",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: validate OSD extent maps before cursor advance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89657"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-89658",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89658"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-89659",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Prevent client use-after-free during delegation revoke",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89659"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-89660",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Prevent client use-after-free during admin state revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89660"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-89661",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Prevent post-shutdown use-after-free in unlock_filesystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89661"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-89662",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Prevent lock owner use-after-free during client teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89662"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-89663",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: revoke copy-notify stateids before dropping their reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89663"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-89664",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: release OPEN-decoded posix ACLs via op_release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89664"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-89665",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89665"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-89666",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89666"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-89667",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89667"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-89668",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89668"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-89669",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: initialize copy-notify stateid before publishing it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89669"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-89670",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: hold rcu across localio cmpxchg retry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89670"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-89671",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: gate nfs3 setacl by argp->mask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89671"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-89672",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: gate nfs2 setacl by argp->mask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89672"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-89673",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89673"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-89674",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89674"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-89675",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix UAF in async copy cancel and shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89675"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-89676",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix stale s2s_cp_stateids IDR entry for async COPY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89676"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-89677",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89677"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-89678",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix partial-write detection in nfsd_direct_write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89678"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-89679",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89679"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-89680",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix nfsd_file leak on inter-server COPY setup failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89680"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-89681",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix layout fence worker double-reference race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89681"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-89682",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89682"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-89683",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix dentry ref leak on V4ROOT export filehandle lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89683"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-89684",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix cpntf publish race in nfs4_init_cp_state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89684"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-89685",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix clock domain mismatch in clients_still_reclaiming()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89685"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-89686",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89686"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-89687",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89687"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-89688",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: drop the stateid, not the stateowner, on seqid_op replay retry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89688"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-89689",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: don't free session slots that are still in use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89689"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-89690",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: defer vfree of compound ops to fix rpc_status UAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89690"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-89691",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: clear opcnt on compound arg release to prevent OOB read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89691"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-89692",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: clear CALLBACK_RUNNING on failed delegation recall queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89692"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-89693",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89693"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-89694",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: check client ownership when cancelling a copy-notify stateid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89694"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-89695",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: cap decoded POSIX ACL count to bound sort cost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89695"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-89696",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89696"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-89697",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89697"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-89698",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89698"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-89699",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: validate symlink target length in NFSv4 CREATE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89699"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-89700",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: validate sockaddr length per family in listener_set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89700"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-89701",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: validate nseconds in TIME_DELEG decode paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89701"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-89702",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: size fh_verify server sockaddr slot by xpt_locallen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89702"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-89703",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89703"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-89704",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: sample writeback error cursor before async COPY loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89704"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-89705",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89705"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-89706",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: Reset write verifier when async COPY writeback fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89706"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-89707",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: release path refs on follow_down() error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89707"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-89708",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89708"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-89709",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "lockd, nfsd: RCU-protect nlmsvc_ops dispatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89709"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-89710",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89710"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-89711",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89711"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-89712",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89712"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-89713",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: check truncate permission under inode lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89713"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-89714",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89714"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-89715",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFS/localio: fix ref leak on nfs_uuid_add_file failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89715"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-89716",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "zram: validate deflate params",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89716"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-89717",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "zram: set default primary compressor in zram_destroy_comps()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89717"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-89718",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "zram: fix out-of-bounds access in writeback_store()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89718"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-89719",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "zram: fix out-of-bounds access in read_block_state()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89719"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-89720",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ubifs: fix out-of-bounds read in signature length check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89720"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-89721",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phy: rockchip-samsung-dcphy: fix out-of-range max_register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89721"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-89722",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89722"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-89723",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89723"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-89724",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: vicodec: fix out-of-bounds write in FWHT encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89724"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-89725",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cec: stm32: prevent out-of-bounds write on RX overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89725"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-89726",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89726"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-89727",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89727"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-89728",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: renesas: Fix out-of-bounds access for newdevs mask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89728"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-89729",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89729"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-89730",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89730"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-89731",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89731"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-89732",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_fs: Prevent deadlock during ep0 read loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89732"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-89733",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89733"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-89734",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89734"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-89735",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: midi2: remove default configfs groups on teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89735"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-89736",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: u_audio: Fix use-after-free on sound card disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89736"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-89737",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: typec: thunderbolt: Disable work before freeing tbt on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89737"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-89738",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89738"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-89739",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89739"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-89740",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "serial: imx: serialize imx_uart_ports[] lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89740"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-89741",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Revert \"media: v4l2-dev: fix error handling in __video_register_device()\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89741"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-89742",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rapidio: mport_cdev: fix use-after-free in dma_req_free()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89742"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-89743",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "misc: nsm: bound the device-reported response length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89743"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-89744",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "device property: fix infinite loop in fwnode_for_each_child_node()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89744"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-89745",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "debugfs: Fix lockdown check for mmap_prepare",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89745"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-89746",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix use-after-free with same-name named triggers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89746"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-89747",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix use-after-free in trace_pipe read on sub-buffer order change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89747"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-89748",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix retry exhaustion in simple ring buffer reader swap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89748"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-89749",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix crash passing ERR_PTR to kthread_stop()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89749"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-89750",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing/user_events: Clear copied tracing state before fork duplication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89750"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-89751",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/tdx: Fix off-by-one in port I/O handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89751"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-89752",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm: memcg: stop reclaim when a limit update is superseded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89752"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-89753",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89753"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-89754",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/pagewalk: fix stale walk->action escaping walk_pmd_range()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89754"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-89755",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/migrate_device: clear stale mapping after freeing swapcache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89755"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-89756",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89756"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-89757",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/mglru: fix and remove redundant unevictable folio handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89757"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-89758",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/mempolicy: skip non-present PMDs when queueing folios",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89758"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-89759",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/kmemleak: avoid soft lockup when scanning task stacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89759"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-89760",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm, swap: don't free a hibernation slot that is in the swap cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89760"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-89761",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "apparmor: fix out-of-bounds write when null terminating a label vec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89761"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-89762",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "apparmor: fix cred UAF caused by begin_current_label_crit_section()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89762"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-89763",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KEYS: trusted: Fix TPM teardown ordering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89763"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-89764",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rust: devres: fix race between concurrent revokers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89764"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-89765",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "timers/itimer: Zero-init old itimerval before copy to userspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89765"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-89766",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pidfd: hold exec_update_lock around namespace ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89766"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-89767",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovl: fix double end_creating() on the casefold-mismatch path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89767"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-89768",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs: fix user path of nested backing files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89768"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-89769",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89769"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-89770",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iomap: don't free integrity payload that doesn't exist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89770"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-89771",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Fix subbuf resize race with ring buffer readers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89771"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-89772",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: write-protect folios during data writeback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89772"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-89773",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: Skip Update HDCP Config In Transition State",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89773"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-42016",
      "detail": "ADDED TO KEV — CVE-2026-42016 (jfrog artifactory). Remediation due September 25, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-42018",
      "detail": "ADDED TO KEV — CVE-2026-42018 (jfrog artifactory). Remediation due September 25, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-84869",
      "detail": "ADDED TO KEV — CVE-2026-84869 (ConnectWise ScreenConnect). Remediation due September 14, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-85706",
      "detail": "ADDED TO KEV — CVE-2026-85706 (GitLab). Remediation due September 14, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13608",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13608 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16033 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18924",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18924 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19931",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19931 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29181",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42264",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42264 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42338",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42578",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42578 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42581",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42581 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42584 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42587",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42587 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44486 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44487 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44488 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44492 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44494",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44494 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44495 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44496 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45736",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48779",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58592",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58592 (LadybirdBrowser Ladybird). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62420",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62420 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63294",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63294 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63295",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63295 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63296",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63296 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63297",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63297 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63298",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63298 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63299",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63299 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63300",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63300 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66897",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66897 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66898",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66898 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67292",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67292 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67294",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67294 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67296",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67296 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67297",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67297 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70473",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70473 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70474",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70474 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70476",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70476 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73309",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73309 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73310",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73310 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73311",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73311 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73312",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73312 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73313",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73313 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73314",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73314 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73315",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73315 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73316",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73316 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73317",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73317 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73318",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73318 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73319",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73319 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73320",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73320 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73321",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73321 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73694",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73694 (FileRun). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74239",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74239 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79698",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79698 (Advantech WISE-6610-NB). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80229",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80229 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80230",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80230 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80231",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80231 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80255",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80255 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82208",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82208 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82209",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82209 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82537",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82537 (RooCodeInc Roo-Code). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85378",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85378 (light0011 cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85383",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85383 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85402",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85402 (code-projects Doctor Appointment System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85408",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85408 (Eleveo Quality Management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85516",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85516 (code-projects Vehicle Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85638",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85638 (jofpin trape). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85703",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85703 (ramon-victor freegpt-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86161",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86161 (SourceCodester Online Voting System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86166",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86166 (Tenda HG10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86172",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86172 (DefaultFuction CRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86183",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86183 (diem-project diem). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86212",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86212 (Open5GS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86217",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86217 (code-projects Hotel and Tourism Reservation in PHP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86224",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86224 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86231",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86231 (mwiede jsch). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86236",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86236 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86241 (liufee FeehiCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86262",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86262 (sfturing hosp_order). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86268",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86268 (itsourcecode School Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86273",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86273 (projeto-siga siga). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86281",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86281 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86289",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86289 (Ollama). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86294",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86294 (SourceCodester Simple Traffic Offense System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86299",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86299 (Linksys RE7000). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86305",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86305 (light0011 cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86310",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86310 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86509",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86509 (D-Link DIR-895L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86514",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86514 (vgmstream). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86519",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86519 (code-projects Student Crud Operation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86668",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86668 (aircheng-org iWebShop-5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86672",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86672 (ningzichun Student Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86674",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86674 (ningzichun Student Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86808",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86808 (moltis-org moltis). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87468",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87468 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87493",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87493 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87580",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87580 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87584 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87589",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87589 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87923",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87923 (Rizwan17 inventory-management-system). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-66384",
      "detail": "DUE DATE PASSED — CVE-2026-66384 (jfrog artifactory). CISA remediation deadline was September 10, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65646",
      "detail": "RESCORED — CVE-2026-65646 (WebPros Plesk). CVSS 8.7 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69224",
      "detail": "RESCORED — CVE-2026-69224 (Esri Portal for ArcGIS). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69225",
      "detail": "RESCORED — CVE-2026-69225 (Esri Portal for ArcGIS). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69230",
      "detail": "RESCORED — CVE-2026-69230 (Esri Portal for ArcGIS). CVSS 5.5 → 4.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69237",
      "detail": "RESCORED — CVE-2026-69237 (Esri Portal for ArcGIS). CVSS 3.8 → 4.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69238",
      "detail": "RESCORED — CVE-2026-69238 (Esri Portal for ArcGIS). CVSS 3.5 → 4.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80133",
      "detail": "RESCORED — CVE-2026-80133 (Dell Secure Connect Gateway 5.0 - Application). CVSS 7.4 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80135",
      "detail": "RESCORED — CVE-2026-80135 (Dell Secure Connect Gateway 5.0 - Application). CVSS 7.5 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80178",
      "detail": "RESCORED — CVE-2026-80178 (Dell Secure Connect Gateway 5.0 - Application). CVSS 5.5 → 7.8 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-82455",
      "detail": "REJECTED — CVE-2026-82455 (rubygems). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-81789",
      "detail": "PATCH SHIPPED — CVE-2026-81789 (Studio Wombat Advanced Product Fields Extended for WooCommerce). Fixed in Advanced Product Fields Extended for WooCommerce 3.1.7."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-86169",
      "detail": "PATCH SHIPPED — CVE-2026-86169 (axolotl-ai-cloud axolotl). Fixed in axolotl 0.19.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-87875",
      "detail": "PATCH SHIPPED — CVE-2026-87875 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.4.19-4.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-89060",
      "detail": "PATCH SHIPPED — CVE-2026-89060 (multicluster-observability-addon). Fixed in multicluster-observability-addon ad36a3ba9fd946c04de71621e47486f7aa2634fd."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
