Security Box Score — September 17, 2026 — page 3
Edition of September 17, 2026, continued — page 3 of 3. Back to page 1 · page 2
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-93186 | await | — | Linux | Linux | — | cxl/mbox: Clamp mailbox output allocation to the payload size |
| CVE-2026-93187 | await | — | Linux | Linux | — | ASoC: SOF: ipc4-topology: Return error for invalid number of formats |
| CVE-2026-93188 | await | — | Linux | Linux | — | HID: roccat: bound device-supplied profile index |
| CVE-2026-93189 | await | — | Linux | Linux | — | HID: core: quiesce input in hid_hw_stop() to prevent use-after-free |
| CVE-2026-93190 | await | — | Linux | Linux | — | platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count |
| CVE-2026-93191 | await | — | Linux | Linux | — | smack: fix incorrect task context in smack_msg_queue_msgrcv |
| CVE-2026-93192 | await | — | Linux | Linux | — | drm/v3d: Clear queue->active_job when v3d_fence_create() fails |
| CVE-2026-93193 | await | — | Linux | Linux | — | drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup |
| CVE-2026-93194 | await | — | Linux | Linux | — | drm/rockchip: dw_dp: Release core resources |
| CVE-2026-93195 | await | — | Linux | Linux | — | drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel |
| CVE-2026-93196 | await | — | Linux | Linux | — | nvdimm: virtio_pmem: refcount requests for token lifetime |
| CVE-2026-93197 | await | — | Linux | Linux | — | memcg: move LRU size accounting on reparenting instead of copying it |
| CVE-2026-93198 | await | — | Linux | Linux | — | dm-pcache: validate the persisted dirty_tail chain at load |
| CVE-2026-93199 | await | — | Linux | Linux | — | i3c: master: Do not treat master device as a duplicate target |
| CVE-2026-93200 | await | — | Linux | Linux | — | i3c: master: Fix use-after-free of master->this |
| CVE-2026-93201 | await | — | Linux | Linux | — | dm-pcache: validate seg_id fields from persistent memory |
| CVE-2026-93202 | await | — | Linux | Linux | — | i3c: master: Fix recursive locking during device registration |
| CVE-2026-93203 | await | — | Linux | Linux | — | batman-adv: bla: avoid CRC corruption due to parallel claim add |
| CVE-2026-93204 | await | — | Linux | Linux | — | batman-adv: dat: atomically update mac addresses |
| CVE-2026-93372 | await | — | Chrome | CWE-121 | Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.5… | |
| CVE-2026-93373 | await | — | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed … | |
| CVE-2026-93374 | await | — | Chrome | CWE-416 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 … | |
| CVE-2026-93375 | await | — | Chrome | CWE-706 | Incorrect reference resolution in Tracing in Google Chrome on on Windows prio… | |
| CVE-2026-93376 | await | — | Chrome | CWE-125 | Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 al… | |
| CVE-2026-93377 | await | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote… | |
| CVE-2026-93378 | await | — | Chrome | CWE-862 | Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allo… | |
| CVE-2026-93379 | await | — | Chrome | CWE-863 | Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowe… | |
| CVE-2026-93380 | await | — | Chrome | CWE-367 | Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed … | |
| CVE-2026-93381 | await | — | Chrome | CWE-122 | Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.… | |
| CVE-2026-93382 | await | — | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a re… | |
| CVE-2026-93383 | await | — | Chrome | CWE-200 | Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allow… | |
| CVE-2026-93384 | await | — | Chrome | CWE-918 | Server-side request forgery in Omnibox in Google Chrome on on Android prior t… | |
| CVE-2026-93385 | await | — | Chrome | CWE-200 | Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a r… | |
| CVE-2026-93386 | await | — | Chrome | CWE-451 | UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.5… | |
| CVE-2026-93387 | await | — | Chrome | CWE-754 | Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 all… |