2026 · High
High-severity vulnerabilities disclosed in 2026
High-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.
4140 published vulnerabilities · page 21 of 42
- CVE-2026-43724HIGH 7.8
A vulnerability in Apple's operating systems allows a malicious application to terminate the system unexpectedly or write data directly into kernel memory—the privileged core of the operating system. The flaw stems from insufficient validation of user-supplied input. An attacker would need to first gain the ability to run code on the target device, but once installed, the app requires no special permissions or user interaction to trigger the vulnerability. This is a serious local privilege escalation risk affecting iPhones, iPads, and Mac computers.
- CVE-2026-43958HIGH 7.8
CVE-2026-43958 is a stack-based buffer overflow vulnerability in rrdcached, the caching daemon component of rrdtool (a time-series data storage and graphing tool commonly used in network monitoring and systems management). An attacker with local access to the rrdcached socket can trigger the flaw by sending a specially crafted CREATE request with an oversized payload. Successful exploitation could crash the daemon, causing service disruption, or potentially enable arbitrary code execution with the privileges of the rrdcached process.
- CVE-2026-44274HIGH 7.8
Dell Wyse Management Suite (WMS) contains a flaw that allows an attacker with basic user privileges and local system access to bypass file access controls through improper link resolution. This could enable unauthorized access to sensitive system files or data that the attacker should not normally be able to read or modify. The vulnerability affects all versions before WMS 2605 and requires the attacker to already have a user account on the affected system.
- CVE-2026-44802HIGH 7.8
A memory safety flaw in the Windows Desktop Window Manager (DWM) Core Library allows a logged-in user to crash the system or potentially run code with elevated privileges. The vulnerability stems from use-after-free code—a situation where freed memory is accessed again—affecting multiple versions of Windows 10, Windows 11, and Windows Server. An attacker must already have a user account on the machine to exploit it, making this a local privilege escalation risk rather than a remote attack vector.
- CVE-2026-44803HIGH 7.8
An integer overflow vulnerability exists in the Windows graphics subsystem (Win32K) that could allow an attacker with local access to execute code with system privileges. The flaw resides in graphics processing routines and can be triggered through user interaction, such as opening a specially crafted document in Microsoft Office applications. While exploitation requires local system access and user action, successful exploitation grants complete control over an affected system.
- CVE-2026-44804HIGH 7.8
A use-after-free flaw in Windows Desktop Window Manager (DWM) Core Library permits an authorized local user to escalate their privileges to a higher level of system access. The vulnerability requires legitimate account credentials and local system access but does not require user interaction. An attacker with such access could exploit this flaw to gain elevated permissions and control critical system functions.
- CVE-2026-44807HIGH 7.8
A use-after-free memory flaw exists in Windows DWM (Desktop Window Manager) Core Library that allows an authenticated local user to escalate their privileges. An attacker who already has user-level access to a system can exploit this to gain system or administrator-level control. The vulnerability requires local access and user interaction is not needed once an attacker is on the machine.
- CVE-2026-44808HIGH 7.8
A memory corruption flaw in Windows Desktop Window Manager (DWM) Core Library allows a user with local system access to escalate their privileges to a higher level of system access. The vulnerability stems from improper handling of memory buffers and requires an authenticated user to trigger, but does not require user interaction once triggered. This is a local privilege escalation vector that could allow an attacker with initial system access to gain administrative control.
- CVE-2026-44809HIGH 7.8
A use-after-free vulnerability exists in Windows' Common Log File System Driver that allows a user with local access to elevate their privileges to a higher level of system access. While the attacker must already have an account and authentication on the target system, the flaw enables them to break out of their current permission boundary and gain full control. This is a local privilege escalation (LPE) vulnerability affecting recent Windows 11 and Windows Server 2025 versions.
- CVE-2026-44811HIGH 7.8
A heap-based buffer overflow exists in Windows DWM (Desktop Window Manager) Core Library that allows a user already logged into a Windows 11 system to elevate their privileges to a higher level of access. An attacker with an existing local account would need to craft specific input or manipulate the DWM process to trigger the memory corruption, potentially gaining system-level permissions. This is a local-only vulnerability and does not enable remote compromise.
- CVE-2026-44812HIGH 7.8
A flaw in Windows graphics handling (Win32K subsystem) allows a local attacker to crash or take control of a system by exploiting how the operating system processes certain numeric values. The vulnerability requires user interaction—such as opening a specially crafted document in Word, Excel, or PowerPoint—but once triggered, grants full system access. It affects Windows 10, Windows 11, and Windows Server platforms spanning multiple recent versions.
- CVE-2026-44813HIGH 7.8
A use-after-free flaw in Windows Desktop Window Manager (DWM) Core Library allows someone with local system access to escalate their privileges to a higher level of system control. An authenticated attacker—someone already logged into the machine—can exploit this memory safety issue without user interaction to gain elevated permissions, potentially taking full control of the system.
- CVE-2026-44817HIGH 7.8
A type confusion vulnerability in Microsoft Office Excel enables local code execution when a user opens a malicious file. An attacker would craft a specially formatted Excel document that exploits how the application handles certain data types in memory, allowing arbitrary code to run with the privileges of the user who opened the file. This is a local attack requiring user interaction—the victim must open the malicious spreadsheet—but once triggered, it grants full system compromise capabilities.
- CVE-2026-44819HIGH 7.8
A heap-based buffer overflow vulnerability exists in Microsoft Office that allows an attacker to execute arbitrary code on a victim's system. The attack requires local access and user interaction—specifically, the user must open a specially crafted Office document. Once triggered, the vulnerability grants the attacker the same permissions as the logged-in user, potentially compromising sensitive data, modifying files, or installing malware. This is a significant local privilege escalation and code execution risk affecting multiple Office versions and SharePoint Server.
- CVE-2026-44820HIGH 7.8
CVE-2026-44820 is a memory safety vulnerability in Microsoft Office Excel that allows an attacker to read memory outside the intended boundaries and execute arbitrary code. The attack requires local access to the machine and user interaction—typically opening a malicious file—but does not require elevated permissions. Once triggered, the attacker gains the same privileges as the user running Excel, making this a serious threat to any organization relying on Office for routine work.
- CVE-2026-44823HIGH 7.8
Microsoft Office Excel contains a numeric truncation bug that can allow an attacker to run malicious code on a user's computer. The flaw is triggered when a user opens or works with a specially crafted Excel file, making it a local-execution risk. Since no authentication is required and user interaction (opening a file) is the only barrier, this poses a meaningful threat to organizations where Excel is widely used.
- CVE-2026-44824HIGH 7.8
A heap-based buffer overflow vulnerability exists in Microsoft Office that allows an attacker to run malicious code on a user's computer. The vulnerability requires user interaction—such as opening a specially crafted document—but does not require the attacker to be logged in or have elevated permissions. Successful exploitation can lead to complete compromise of the affected system, including theft of sensitive data and installation of malware.
- CVE-2026-45174HIGH 7.8
CVE-2026-45174 is a privilege escalation vulnerability in Palo Alto Networks' Idira Endpoint Privilege Manager Linux Agent that allows a local user with basic system access to compromise the agent daemon during its initialization. An attacker with low-level user privileges can exploit weak initialization controls to gain unauthorized system access with full read, write, and execute capabilities on the affected system. The vulnerability affects all Linux Agent versions before 26.5.
- CVE-2026-45175HIGH 7.8
Idira Endpoint Privilege Manager Agent (versions before 26.5) has a flaw in how it validates itself and enforces security rules. A local user on an affected system could exploit this weakness to bypass the agent's built-in protections and potentially execute actions that should be blocked. The vulnerability requires local access and authenticated login, but once exploited, could allow unauthorized operations at a high privilege level.
- CVE-2026-45176HIGH 7.8
Idira Endpoint Privilege Manager Agent contains a flaw in how it controls access to high-privileged components. An attacker with a regular user account on the same system can manipulate how the agent communicates internally or intercept file operations to trick it into performing actions it shouldn't allow. This could let them gain elevated privileges and take unauthorized actions on the machine. The vulnerability affects versions before 26.5.
- CVE-2026-45195HIGH 7.8
A vulnerability in Imagination Technologies' GPU driver (DDK) allows a local user with basic privileges to send specially crafted commands to the GPU firmware that bypass memory access controls. This can result in reading or writing to memory regions outside what the kernel should be permitted to access, potentially enabling privilege escalation or data theft on systems running affected GPU drivers.
- CVE-2026-45257HIGH 7.8
A vulnerability in FreeBSD's kernel TLS (KTLS) implementation allows an unprivileged local user to overwrite arbitrary files on the system. The flaw stems from the KTLS receive path decrypting data in place without properly handling file-backed memory. When a user sends a file via sendfile(2) over a loopback connection with KTLS receive enabled, the decryption operation overwrites the original file's contents instead of a private copy. An attacker can exploit this to corrupt or replace critical system files, including setuid binaries, achieving local privilege escalation and potential full system compromise.
- CVE-2026-45258HIGH 7.8
A memory validation flaw in FreeBSD's audio device driver allows unprivileged users to bypass security boundaries and access kernel memory. The `/dev/dsp` device—typically world-readable—permits any local user to exploit an integer overflow in the memory mapping validation logic, enabling them to read and modify kernel data, escalate privileges, or crash the system. The vulnerability exists because the kernel checks an arithmetic sum that can wrap around, making the overflow check unreliable.
- CVE-2026-45322HIGH 7.8
Microsoft's UFO framework, an open-source tool for automating tasks across devices, contains a command injection flaw in its shell execution component. An attacker with write access to UFO's session files can embed malicious system commands that execute with the privileges of the UFO process when a session is resumed or replayed. This creates a local privilege escalation risk in environments where session files may be accessible or shared.
- CVE-2026-45353HIGH 7.8
Electerm, an open-source multi-protocol terminal and remote access client supporting SSH, SFTP, Telnet, serial ports, RDP, VNC, Spice, and FTP, contains a high-severity vulnerability affecting versions 3.0.6 through 3.8.8. The issue stems from improper file permissions and unsafe code execution patterns that allow a local attacker with standard user privileges to gain full control over system resources—reading sensitive data, modifying files, and disrupting availability. The vulnerability is resolved in version 3.9.0.
- CVE-2026-45457HIGH 7.8
A flaw in Microsoft Office Word can allow an attacker to read memory outside the intended bounds and execute malicious code on a user's computer. The attack requires local access and user interaction—someone must open a specially crafted Word document. Once triggered, the vulnerability gives an attacker full control over the affected machine, including the ability to read sensitive data, modify files, or install malware.
- CVE-2026-45469HIGH 7.8
Microsoft Office Excel contains an integer underflow vulnerability that allows a local attacker to execute arbitrary code on a victim's machine. The flaw resides in how Excel processes certain numeric values internally, causing memory management errors. An attacker must convince a user to open a specially crafted spreadsheet file to trigger the vulnerability. Once code execution is achieved, the attacker gains the same privileges as the user running Excel, potentially enabling data theft, malware installation, or lateral movement within the organization.
- CVE-2026-45471HIGH 7.8
A vulnerability in Microsoft Office Word allows an attacker to execute arbitrary code on a victim's computer by exploiting improper handling of pointers in memory. An attacker would need to trick a user into opening a malicious Word document; once opened, the flaw enables local code execution with the privileges of the logged-in user. This is a local attack that requires user interaction but poses significant risk to confidentiality, integrity, and availability of the affected system.
- CVE-2026-45475HIGH 7.8
Microsoft Office contains a heap-based buffer overflow vulnerability that allows an attacker with local access to execute arbitrary code with the privileges of the user running Office. The flaw requires user interaction—such as opening a malicious document—but once triggered, provides complete control over the affected system. This is a serious local privilege escalation risk for organizations relying on Microsoft Office across their workforce.
- CVE-2026-45486HIGH 7.8
A use-after-free vulnerability in Microsoft Office Word allows an attacker with local system access to execute arbitrary code by manipulating memory that has already been freed. The flaw requires user interaction—specifically opening a malicious document—but once triggered, grants the attacker full system-level privileges. This is a local execution vulnerability, not a network-based attack, meaning the attacker must either have initial access to the machine or trick a user into opening a hostile file.
- CVE-2026-45487HIGH 7.8
A timing-based vulnerability exists in Windows' Program Compatibility Assistant Service that allows someone with local system access to exploit a gap between checking permissions and using a resource. By executing commands at precisely the right moment, an attacker can bypass normal privilege restrictions and gain elevated access to the system. This is a local-only attack requiring the attacker to already have a user account on the machine.
- CVE-2026-45490HIGH 7.8
A flaw in Microsoft .NET allows an authorized local user to bypass privilege restrictions and gain higher-level access on the same machine. An attacker who already has login credentials can exploit this improper authorization logic to escalate to administrative or system-level permissions, potentially compromising the entire system.
- CVE-2026-45555HIGH 7.8
Roslyn CodeLens MCP Server, a tool that provides intelligent code analysis for .NET projects, contains a critical flaw in how it handles diagnostic analyzers. When you open a .NET solution, the server automatically loads and runs all diagnostic analyzer assemblies referenced in the project files without checking whether they're legitimate. An attacker can exploit this by crafting a malicious project file that references a malicious DLL. When a developer opens that project with the MCP server, the attacker's code runs with the same privileges as the server process, potentially compromising the entire development environment.
- CVE-2026-45586HIGH 7.8
A flaw in Windows Collaborative Translation Framework allows a user with local access to escalate their privileges by exploiting how the system handles symbolic links and file access. An attacker who already has a standard user account can manipulate file paths to trick the system into accessing files with elevated permissions, gaining full control of the affected machine.
- CVE-2026-45592HIGH 7.8
A flaw in Windows Internet (wininet.dll) allows a logged-in user to gain elevated system privileges through an integer overflow condition. The vulnerability requires local access and an existing user account, but does not need user interaction once exploited. This is a local privilege escalation path that impacts a wide range of Windows versions, from Windows 10 through the latest Windows 11 and several Windows Server editions.
- CVE-2026-45593HIGH 7.8
A use-after-free memory flaw in the Windows SDK enables a user with local access to gain elevated privileges on affected Windows systems. The vulnerability requires the attacker to be authenticated and logged in, but does not need user interaction to trigger. An attacker exploiting this could gain System-level access, potentially allowing them to install malware, modify system configurations, or access sensitive data.
- CVE-2026-45600HIGH 7.8
A type confusion flaw exists in Windows kernel-mode drivers that allows a user already logged into a Windows system to escalate their privileges to a higher level of access. An attacker would need valid credentials and local access to exploit this issue. The vulnerability affects recent versions of Windows 11 and Windows Server 2025.
- CVE-2026-45605HIGH 7.8
A use-after-free vulnerability in Windows Bluetooth Service enables local privilege escalation when exploited by an authenticated user. The flaw resides in memory management within the Bluetooth subsystem, allowing an attacker with valid credentials to corrupt memory and gain higher system privileges. This is not a remote attack and requires prior local access to the system.
- CVE-2026-45636HIGH 7.8
A heap-based buffer overflow vulnerability exists in Windows NTFS that allows an attacker with local access to execute arbitrary code on affected systems. The vulnerability requires user interaction—such as opening a specially crafted file—but does not require elevated privileges to trigger. Once exploited, an attacker can achieve full system compromise including reading sensitive data, modifying files, and disrupting system availability.
- CVE-2026-45637HIGH 7.8
A use-after-free vulnerability exists in the Windows Desktop Window Manager (DWM) Core Library that allows an authorized local user to escalate their privileges to a higher level of system access. The vulnerability requires the attacker to already have local logon capability and is not remotely exploitable. This type of flaw occurs when software continues to reference memory that has been freed, potentially allowing an attacker to manipulate that memory and gain elevated permissions.
- CVE-2026-45638HIGH 7.8
A memory corruption flaw in Windows' Ancillary Function Driver for WinSock can allow an attacker with local system access to bypass privilege controls and gain full administrative rights. The vulnerability exists in how the driver handles network socket operations and does not require user interaction to exploit. An attacker would need to already have a foothold on the machine, but once they do, this bug becomes a direct path to system-level control.
- CVE-2026-45643HIGH 7.8
Microsoft Office Word contains a vulnerability where untrusted data is dereferenced as a pointer without proper validation, allowing an attacker to execute arbitrary code on a system where Word is installed. The attack requires user interaction—specifically opening a malicious document—but does not require elevated privileges. This is a local code execution issue affecting multiple versions of Microsoft Office and Microsoft 365 Apps.
- CVE-2026-45645HIGH 7.8
CVE-2026-45645 is a high-severity memory safety vulnerability in Microsoft Office that enables local code execution. An attacker who gains access to a user's system can craft a malicious Office document that, when opened by the user, exploits improper pointer handling to run arbitrary code with the privileges of the person viewing the file. This requires user interaction (opening a document) but no special permissions to trigger.
- CVE-2026-45656HIGH 7.8
A flaw in Windows UEFI firmware allows someone with local access to bypass a built-in security protection. The attacker must already have basic user privileges on the system, but once exploited, they can read sensitive data, alter system files, or disable critical functions. This is a protection mechanism failure—think of it as a lock that should prevent unauthorized actions but doesn't work correctly under certain conditions.
- CVE-2026-45658HIGH 7.8
A flaw in Windows BitLocker's access controls allows someone with local system access to circumvent the encryption security feature. An authorized user—such as an administrator or service account—can exploit this weakness to bypass BitLocker protections without requiring additional authentication or user interaction. This is a local-only attack and does not grant network-based access, but it significantly weakens the confidentiality and integrity guarantees that BitLocker is meant to provide.
- CVE-2026-46105HIGH 7.8
A flaw in the Linux kernel's mpt3sas driver allows NVMe storage controllers to accept I/O requests larger than the driver can safely handle. The driver allocates a fixed 4 KB buffer that can hold at most 512 entries in its request queue (PRP list), limiting safe transfers to 2 MiB. However, the firmware may advertise support for larger transfers based on the drive's capabilities. When oversized requests are issued, the kernel can crash. This vulnerability requires local access and valid user privileges to exploit.
- CVE-2026-46107HIGH 7.8
A bug in the Linux kernel's device mapper thin provisioning layer can cause reference counting errors when managing shared metadata trees. When the kernel tries to reorganize a btree node that has been shared across multiple data structures, it fails to properly track pointers to child nodes, leading to crashes and data unavailability. The flaw occurs specifically in the rebalance_children function during metadata tree operations.
- CVE-2026-46111HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Bluetooth connection handling code. When creating a Broadcast Isochronous Group (BIG) connection, the kernel can attempt to access a connection object that has already been freed. This occurs because the code doesn't properly validate that a connection still exists before operating on it, and doesn't keep a reference to the connection object while asynchronous operations are in flight. A local attacker with limited privileges could exploit this to crash the system or potentially execute code with elevated privileges.
- CVE-2026-46112HIGH 7.8
A locking bug exists in the Linux kernel's RDMA HNS driver when creating queue pairs. During error recovery in queue pair creation, the code attempts to clean up resources without holding required synchronization locks. This unlocked cleanup can corrupt internal kernel memory structures, potentially allowing a local attacker to escalate privileges or crash the system. The vulnerability affects the error handling path specifically—the normal operation path uses proper locking.
- CVE-2026-46116HIGH 7.8
A memory safety bug exists in the Linux kernel's IPsec implementation where the xfrm_state subsystem can encounter use-after-free errors when network security policies are deleted or when network namespaces are torn down. The kernel's code was using inconsistent methods to track whether data structures were properly removed from internal lists, causing the same memory region to sometimes be deleted twice. This corrupts kernel memory and can lead to privilege escalation or denial of service on affected systems.
- CVE-2026-46117HIGH 7.8
A flaw in the Linux kernel's RDMA/mana driver allows unprivileged local users to trigger a kernel warning and corrupt memory by creating queue pairs (QPs) that share the same completion queue (CQ) through the user-space API. The vulnerability bypasses validation logic that should reject this invalid configuration, leading to kernel memory corruption. The fix enforces proper validation to reject such requests at creation time rather than allowing them to proceed and corrupt state.
- CVE-2026-46120HIGH 7.8
A flaw in the Linux kernel's IPv6 GRE tunnel implementation allows a local attacker with unprivileged user namespace capabilities to trigger memory corruption. The vulnerability stems from inconsistent netns (network namespace) handling in the ip6erspan_changelink() function, which fails to use the correct cached network namespace context when reconfiguring an ERSPAN tunnel after it has been migrated between namespaces. This can lead to kernel crashes and potential privilege escalation.
- CVE-2026-46121HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's DAMON (Data Access Monitoring) subsystem, specifically in how it manages memory cgroup path strings through its sysfs interface. When users read and write the 'memcg_path' file concurrently using separate file handles, a race condition can occur where one process reads a pointer to memory that another process has already freed. This allows an attacker with local access to crash the system or potentially execute code with kernel privileges.
- CVE-2026-46122HIGH 7.8
A flaw exists in the Linux kernel's b43 wireless driver that can allow a local attacker to read memory outside the bounds of an internal array. The issue stems from insufficient validation of a firmware-supplied index value used to access encryption keys. When the firmware provides an invalid index—one larger than the 58-entry key array—the driver does not properly reject it in production systems, leading to an out-of-bounds read. An attacker with local system access could exploit this to leak sensitive kernel memory.
- CVE-2026-46129HIGH 7.8
A double-free memory corruption bug exists in the Linux kernel's Btrfs filesystem implementation. When the kernel initializes and registers filesystem space information objects with the sysfs interface, a failure in that registration process can cause the same memory block to be freed twice. This happens because the error recovery code doesn't account for cleanup already performed by the object release callback. A local attacker with unprivileged user access could trigger this condition and gain kernel-level privileges.
- CVE-2026-46136HIGH 7.8
A flaw in the Linux kernel's MT7921 Wi-Fi driver can cause a buffer length counter to drop below zero under specific conditions when the driver processes country power settings from the Carrier List Configuration (CLC). This underflow triggers either an excessive loop that nearly hangs the system or applies an invalid power setting, preventing the driver from initializing properly. An attacker with local access could exploit this to degrade Wi-Fi functionality or trigger a denial of service.
- CVE-2026-46145HIGH 7.8
CVE-2026-46145 is a memory corruption vulnerability in the Linux kernel's RDMA/mana driver. An unprivileged local user can manipulate a parameter called rx_hash_key_len from user space to cause an unbounded memory copy operation, corrupting kernel memory. The vulnerability stems from insufficient validation of user-supplied input before it is passed to a memory copy function, creating a path for local privilege escalation or system crash.
- CVE-2026-46157HIGH 7.8
A concurrency bug exists in the Linux kernel's ALSA (Advanced Linux Sound Architecture) OSS (Open Sound System) compatibility layer. When multiple processes try to access and modify the trigger control bit simultaneously, the kernel lacks proper synchronization, allowing writes to corrupt not just the intended trigger flag but adjacent bit fields in memory. This confusion can destabilize audio subsystem behavior. The vulnerability requires local access and privileges to trigger.
- CVE-2026-46162HIGH 7.8
A flaw in the Linux kernel's ice (Intel ice) network driver creates a double-free memory corruption condition in the auxiliary device activation error handler. When the driver attempts to activate a subfunction Ethernet device but the operation fails partway through, the error handling code frees the same memory region twice, corrupting the kernel heap. An attacker with local access and unprivileged user privileges can trigger this condition to escalate privileges or crash the system.
- CVE-2026-46163HIGH 7.8
A flaw exists in the Linux kernel's b43legacy wireless driver that fails to properly validate array index bounds when processing incoming wireless frames. The firmware supplies a key index value that the driver uses to access a cryptographic key array, but there is no enforcing check to ensure this index stays within valid bounds. In production builds, this allows an attacker with local access to trigger an out-of-bounds memory read by crafting malicious wireless traffic, potentially exposing sensitive kernel memory or causing a system crash.
- CVE-2026-46173HIGH 7.8
A vulnerability in the Linux kernel allows a task that is already exiting to encounter a coding error that violates critical scheduling rules. Specifically, when a dying task encounters an oops (kernel panic) during its shutdown sequence, the kernel attempts to complete the exit process while preemption is still enabled—a state that violates explicit safety requirements in the scheduler. If the oopsing task is preempted at the wrong moment, the scheduler loses track of the fact that the task is dead and can no longer run, leading it to reuse the task's memory stack. Multiple tasks can then execute on the same stack space, causing memory corruption that can lead to data corruption, information disclosure, or system compromise.
- CVE-2026-46176HIGH 7.8
A flaw in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem for Mellanox adapters causes improper error handling when initializing shared receive queues. When the second queue creation fails, the kernel incorrectly leaves freed memory pointers and error codes in place instead of properly backing out. This can lead to use-after-free conditions and memory corruption when subsequent operations attempt to access or clean up these corrupted pointers.
- CVE-2026-46178HIGH 7.8
A resource management flaw exists in the Linux kernel's RDMA/mlx4 subsystem where memory allocated for Shared Receive Queues (SRQs) is not properly freed when the queue creation process encounters an error. This leaked memory accumulates over time, potentially degrading system performance or causing denial of service if the condition is repeatedly triggered. The issue affects systems using the Mellanox InfiniBand adapter driver on Linux.
- CVE-2026-46180HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Broadcom Wi-Fi driver (brcmfmac) watchdog task shutdown logic. When the kernel stops the watchdog task, a race condition can occur where the task terminates between two function calls, leaving dangling references that code attempts to access. An attacker with local access can exploit this timing weakness to crash the system or potentially execute code with elevated privileges.
- CVE-2026-46181HIGH 7.8
A synchronization flaw in the Linux kernel's RDMA/mlx4 driver allows a local attacker to cause memory corruption or system crash. The vulnerability stems from improper use of Read-Copy-Update (RCU) locking in the mlx4_srq_event() function, which fails to protect against race conditions during Shared Receive Queue (SRQ) initialization and event delivery. An attacker with local access can trigger device events before SRQ objects finish initializing, leading to kernel memory access violations with high impact to confidentiality, integrity, and availability.
- CVE-2026-46183HIGH 7.8
A race condition exists in the Linux kernel's DAMON (Data Access Monitoring) subsystem where multiple processes can simultaneously read and write to a shared memory path variable without proper synchronization. When one process deallocates this buffer while another is reading it, the reader accesses freed memory—a use-after-free condition. The vulnerability requires local system access and standard user privileges to exploit, but grants attackers the ability to read sensitive kernel memory, corrupt data structures, or crash the system. This is a classic synchronization flaw that occurs when direct user-driven file operations bypass the locking mechanisms protecting background parameter-commit operations.
- CVE-2026-46189HIGH 7.8
A flaw in the Linux kernel's RDMA (Remote Direct Memory Access) vmw_pvrdma driver causes the same memory block to be freed twice when certain error conditions occur during user context allocation. When the pvrdma_alloc_ucontext() function encounters an error, it attempts to clean up by calling pvrdma_uar_free(). However, the normal cleanup path (pvrdma_dealloc_ucontext()) also calls this same free function, resulting in a double-free scenario. This type of memory corruption can lead to kernel crashes or potentially be exploited for privilege escalation on systems with unprivileged user access to RDMA devices.
- CVE-2026-46197HIGH 7.8
A validation flaw exists in the Linux kernel's AMD KFD (Kernel Fusion Driver) component that handles GPU compute memory management. The SVM (Shared Virtual Memory) ioctl handler fails to properly validate a user-supplied attribute count field before using it to access a buffer, creating an opportunity for an unprivileged local user to read or write memory outside the intended boundaries. This is a local privilege escalation and information disclosure vulnerability that requires an attacker to already have user-level access to the system.
- CVE-2026-46201HIGH 7.8
A memory management flaw exists in the Linux kernel's display driver for Intel Xe graphics. When importing external memory buffers (dma-buf), the kernel fails to properly clean up an attachment if initialization of the buffer object encounters an error. This leaves orphaned kernel resources and can be exploited by a local user to cause denial of service or potentially escalate privileges.
- CVE-2026-46205HIGH 7.8
A vulnerability exists in the Linux kernel's media staging driver (atomisp) where private IOCTL commands are not properly restricted. An attacker with local access and limited privileges can exploit these IOCTLs to gain elevated read, write, and execution capabilities on the system. The kernel maintainers have addressed this by blocking all private IOCTL commands to the driver, preventing unauthorized kernel-level operations from user-space processes.
- CVE-2026-46206HIGH 7.8
CVE-2026-46206 is a vulnerability in the Linux kernel's batman-adv (Better Approach To Mobile Ad-hoc Networking) module that allows improper state transitions during network teardown. The issue occurs when the tp_meter (throughput meter) component fails to block new measurement sessions after the mesh network has begun shutting down. An attacker with local access can exploit this race condition to initiate sender or receiver sessions on a network that is no longer in an active state, potentially causing privilege escalation or system instability.
- CVE-2026-46208HIGH 7.8
A flaw in the Linux kernel's batman-adv mesh networking module can occur when the mesh interface is shut down. TP meter sessions—which measure link quality and throughput in mesh networks—may continue running even after the user's request has completed. When the mesh is torn down, these orphaned sessions can still be active, allowing incoming packets or sender threads to interact with a mesh instance that is already shutting down. This can lead to memory corruption, privilege escalation, or denial of service. The fix ensures that all active TP meter sessions are properly stopped and cleaned up before the mesh finishes shutting down.
- CVE-2026-46209HIGH 7.8
A calculation error in the Linux kernel's graphics subsystem can cause memory protection checks to fail for certain image formats and dimensions. When the GPU driver prepares framebuffers for display, it validates that allocated memory is large enough. However, a mismatch in how dimensions are rounded between two validation functions can cause this check to incorrectly pass for very small images—specifically those 1 pixel tall with formats like NV12. This allows the GPU to access memory outside its allocated buffer, potentially enabling data theft or system compromise from unprivileged user processes.
- CVE-2026-46210HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's iris media driver that can be triggered when multiple instances operate concurrently. The flaw arises from a timing gap: while one thread checks video format parameters (width and height) during a macro block validation, another thread may simultaneously free those same format structures. This leaves the checker reading memory that has already been released, potentially crashing the kernel or allowing privilege escalation. The vulnerability requires local access and is triggered through normal kernel operations when multiple media encoding or decoding sessions run in parallel.
- CVE-2026-46213HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Apple keyboard HID driver (appletb-kbd). When the driver unloads or encounters an error during initialization, a cleanup race condition allows a timer callback to access freed memory. The timer can fire after the backlight device is deallocated but before the driver has fully stopped listening for hardware events, causing kernel memory corruption. An attacker with local access and the ability to trigger driver unload or timing conditions could crash the system or potentially execute code with kernel privileges.
- CVE-2026-46215HIGH 7.8
A race condition exists in the Linux kernel's DRM (Direct Rendering Manager) subsystem, specifically in the change_handle function. When an application changes a graphics handle, the kernel briefly maintains two references to the same object in its internal tracking structures. A concurrent operation can delete the graphics object while one reference remains valid, leaving a dangling pointer that could later be dereferenced, causing a crash or potential code execution. The fix involves properly nullifying the old handle before performing operations, matching a defensive pattern already used elsewhere in the DRM code.
- CVE-2026-46219HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's MPC52xx SPI driver. When the driver is unbound (e.g., during module unload or device removal), a scheduled work queue task can attempt to access driver state that has already been freed, potentially leading to memory corruption or a kernel crash. The vulnerability arises from a race condition: the interrupt handler schedules work, but the unbind routine disables interrupts without ensuring the scheduled work completes before freeing resources.
- CVE-2026-46227HIGH 7.8
A race condition exists in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation that can lead to use-after-free or type-confusion memory safety violations. The vulnerability occurs when the kernel broadcasts messages to multiple SCTP associations while temporarily releasing the socket lock. During this window, another thread can migrate or free an association that the broadcast operation cached as the next item to process. This can result in the kernel operating on freed memory or misinterpreting data structures, potentially allowing local attackers to gain control over kernel execution flow.
- CVE-2026-46234HIGH 7.8
A logic flaw in the Linux kernel's vsock (virtual socket) subsystem allows memory buffers to grow beyond their intended maximum size. When a user configures socket memory constraints, the kernel checks these limits in the wrong order—it enforces the minimum first, then the maximum. If someone sets a minimum larger than the maximum, the minimum wins and the buffer can balloon past the configured ceiling. This undermines memory isolation and could enable a local attacker to exhaust kernel memory or cause denial of service. The fix reorders the checks so the maximum is always enforced.
- CVE-2026-46240HIGH 7.8
A use-after-free vulnerability was introduced in the Linux kernel's Iris media driver through a recent change meant to improve buffer lifecycle management. The bug occurs in the iris_release_internal_buffers() function, where a buffer object continues to be accessed after it has been freed by a called function. This type of memory safety issue can allow a local attacker with user-level privileges to corrupt kernel memory or execute arbitrary code with kernel privileges.
- CVE-2026-46241HIGH 7.8
CVE-2026-46241 is a use-after-free vulnerability in the Linux kernel's MPC52xx SPI controller driver. When the controller registration process fails, the driver fails to properly clean up allocated interrupt resources. This leaves freed memory accessible, creating a window for potential exploitation and causing a resource leak. The issue affects systems using the MPC52xx SPI controller on Linux and was discovered during a review of related deregistration code.
- CVE-2026-46242HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's event polling (epoll) subsystem. When the kernel removes an epoll watch, it clears a file structure pointer while still actively using that same structure. If another process simultaneously closes the file, a race condition can occur where freed memory gets overwritten with stale data, or worse, memory from one cache gets incorrectly freed to another. This is particularly dangerous when epoll is watching another epoll object (a technique called nested epoll), and requires local access to trigger. An unprivileged user can exploit this to crash the system or potentially escalate privileges.
- CVE-2026-46246HIGH 7.8
A race condition in the Linux kernel's power supply driver (pm8916_lbc) can cause the system to crash or corrupt memory during device removal. The bug stems from a resource initialization order problem: an interrupt handler is registered before its associated data structure (extcon handle) is fully set up. When the device is removed, the data structure gets freed before the interrupt handler is disabled, creating a window where a pending interrupt could try to use already-freed memory. This is a use-after-free vulnerability that requires local access to trigger.
- CVE-2026-46253HIGH 7.8
CVE-2026-46253 is a memory corruption vulnerability in the Linux kernel's pstore/ramoops subsystem—the component responsible for preserving system crash logs and diagnostic data across reboots. The flaw occurs in a function called persistent_ram_save_old() that manages historical crash data. When the kernel tries to save old crash logs, it can allocate a buffer that's too small, then later write more data into it than it can hold. This is a classic heap buffer overflow. The vulnerability requires a very specific sequence of events: a prior crash that didn't fill the entire log buffer, followed by a non-fatal kernel oops (error) that writes a larger log, combined with the pstore background timer being enabled. While the conditions are difficult to meet, when they do occur, an attacker with local access could potentially exploit this to corrupt kernel memory and escalate privileges.
- CVE-2026-46259HIGH 7.8
A vulnerability in the Linux kernel's proc filesystem allows a local attacker with standard user privileges to cause a use-after-free (UAF) condition when reading `/proc/[pid]/stat`. The issue stems from a race condition where the kernel accesses a task's parent process pointer without proper synchronization, creating a window where another CPU can free that pointer concurrently. An attacker can exploit this to read sensitive kernel memory or crash the system.
- CVE-2026-46260HIGH 7.8
A memory safety defect in the Linux kernel's IPv6 routing code allows a local attacker with unprivileged user permissions to read data outside allocated memory boundaries. The vulnerability exists in the `fib6_add_rt2node()` function when processing IPv6 routes created with a specific routing attribute (RTA_NH_ID). Under certain conditions, the kernel reads from memory that doesn't belong to the expected data structure, potentially exposing sensitive kernel data or triggering a crash. The flaw requires local system access and cannot be exploited remotely.
- CVE-2026-46263HIGH 7.8
A bounds-checking flaw in the Linux kernel's AMD display driver can allow an unprivileged local user to read or write kernel memory. The vulnerability exists in the stream encoder initialization code, where an array index is not validated before use. When the engine ID parameter exceeds the valid range (0–4), the code accesses memory outside the intended array, potentially exposing sensitive kernel data or enabling privilege escalation.
- CVE-2026-46267HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's NFC (Near Field Communication) SHDLC (Synchronous Half-Duplex Link Control) driver. The vulnerability occurs during driver shutdown when memory is freed while background timers and worker threads are still active. These timers and workers can attempt to access the freed memory after it has been released, potentially leading to system crashes or privilege escalation. A local attacker with basic user privileges can trigger this condition.
- CVE-2026-46271HIGH 7.8
A vulnerability in the Linux kernel's WiFi driver for Qualcomm's WCN7850 chipset causes the firmware to crash when Wake-on-LAN (WoW) offload features are enabled on multiple network links simultaneously. The issue occurs specifically in multi-link WiFi connections—a feature that allows devices to maintain concurrent connections across different frequency bands. The vulnerability is triggered because the driver was incorrectly applying WoW offload settings to both primary and secondary links, overwhelming the firmware. The fix involves restricting these offload operations to the primary link only, preventing the crash.
- CVE-2026-46274HIGH 7.8
A memory safety bug exists in the Linux kernel's I/O work queue subsystem that can allow a local attacker with user privileges to corrupt kernel memory and crash the system or gain elevated privileges. The vulnerability arises from incomplete validation when removing pending work items from the queue, causing the kernel to retain a dangling pointer to freed memory. When that corrupted pointer is subsequently accessed, it can trigger a write to already-freed kernel structures, leading to heap corruption and potential privilege escalation.
- CVE-2026-46275HIGH 7.8
A series of use-after-free and race condition bugs exist in the Linux kernel's Bluetooth HCI UART driver lifecycle management. The vulnerabilities occur when the driver tears down connections or encounters initialization failures. In particular, if a device disconnects before setup completes, or if multiple operations race during shutdown, the driver may attempt to access memory that has already been freed. This can lead to crashes or potentially allow local code execution. The root cause involves improper ordering of cleanup steps and inadequate synchronization between concurrent workqueues and teardown sequences.
- CVE-2026-46277HIGH 7.8
A vulnerability in the Linux kernel's memory zone device handling allows local attackers with limited privileges to gain elevated access and potentially crash the system. The issue stems from unsafe memory access patterns where the kernel reads from a memory structure (folio) after it has been freed by a device driver, potentially allowing the memory to be reallocated and repurposed. An attacker can exploit this race condition to read sensitive data, modify kernel state, or trigger a denial of service.
- CVE-2026-46279HIGH 7.8
CVE-2026-46279 is a memory management bug in the Linux kernel where pages allocated very early in the boot process—before the page tracking system is fully ready—end up without proper metadata. When these pages are later freed by KASAN (a memory safety tool), the kernel throws a warning because it can't find the tracking information. While this is primarily a diagnostic issue triggered under specific debugging configurations, it indicates a real ordering problem during kernel initialization that needs correction to maintain system stability and prevent potential memory tracking corruption.
- CVE-2026-46280HIGH 7.8
A vulnerability exists in the Linux kernel's HMM (Heterogeneous Memory Management) testing module where device memory pages are not properly returned to system memory when a test file is closed. This creates a situation where the kernel retains references to freed memory structures. If the system later tries to access those orphaned pages—such as during a crash dump—it will attempt to dereference invalid memory pointers, causing a kernel panic. The issue was observed on ARM64 systems during automated testing.
- CVE-2026-46281HIGH 7.8
A memory safety bug exists in the Linux kernel's virtual memory allocation code. When a function called vrealloc_node_align() is asked to reallocate memory under specific conditions—such as when the current allocation is on the wrong NUMA node or violates alignment requirements—it can accidentally write data beyond the boundaries of the newly allocated buffer. This happens because the code copies more data than the new buffer can hold when the reallocation is actually shrinking the requested size. An unprivileged local process can exploit this to overwrite adjacent kernel memory, potentially leading to information disclosure, privilege escalation, or system crashes.
- CVE-2026-46285HIGH 7.8
A use-after-free memory safety bug exists in the Linux kernel's docg3 driver (NAND flash memory controller). When the driver is unloaded or a device is released, a pointer to the main docg3 structure is dereferenced after the memory it points to has already been freed. This can lead to a crash or, in certain conditions, potential code execution. The fix is straightforward: use an already-available pointer to the cascade structure instead of trying to access the freed docg3 object.
- CVE-2026-46294HIGH 7.8
A buffer overflow vulnerability exists in the Linux kernel's device mapper (dm) ioctl subsystem within the retrieve_status function. The flaw occurs when pointer alignment logic fails to validate boundaries before writing data, potentially allowing a local user with elevated privileges to overflow a kernel buffer. However, the practical risk is significantly constrained: the vulnerability requires root access to trigger, and mainstream device mapper libraries (libdevmapper and devicemapper-rs) use 8-byte-aligned buffers that naturally prevent the overflow condition from occurring in typical deployments.
- CVE-2026-46301HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Topcliff PCH SPI driver that occurs when the driver is unbound from a device. The driver attempts to access DMA buffers after they have already been released from memory, potentially causing a crash or allowing local code execution. The flaw stems from improper sequencing during driver unbind—the queue is not flushed before the DMA resources are deallocated, leaving dangling pointers.
- CVE-2026-46308HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's power domain management code for MediaTek processors. The vulnerable function releases a device node reference too early, before checking if a subsequent operation failed. If that operation fails, error-handling code attempts to read the already-freed memory to generate a diagnostic message, potentially causing a crash or memory corruption. An attacker with local system access could exploit this to elevate privileges or cause a denial of service.
- CVE-2026-46311HIGH 7.8
A vulnerability in the Linux kernel's AMD GPU driver allows a local attacker with normal user privileges to corrupt or access kernel memory through improper handling of write-pointer object mappings during GPU queue creation. By unmapping a GPU memory object while queue initialization is in progress and substituting another object at the same memory address, an attacker can trigger a use-after-free condition that grants unauthorized read and write access to kernel memory. The kernel's GPU execution (drm_exec) locking mechanism now properly serializes access to prevent this race condition.