| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-90038 | NFSD: Prevent client use-after-free during export state revocation | Linux | Linux | Critical | 9.8 | 2026-09-16 10:33:37 | Deep Dive |
| CVE-2026-90036 | NFSD: Prevent client use-after-free during blocked-lock reaping | Linux | Linux | Critical | 9.8 | 2026-09-16 10:33:36 | Deep Dive |
| CVE-2026-90012 | spi: Fix DMA mapping ownership on partial map failure | Linux | Linux | Critical | 9.8 | 2026-09-16 10:33:19 | Deep Dive |
| CVE-2026-90011 | scsi: target: iscsi: Reserve a terminator byte for the login payload | Linux | Linux | Critical | 9.1 | 2026-09-16 10:33:19 | Deep Dive |
| CVE-2026-89990 | ceph: lock mutex in ceph_mds_check_access() | Linux | Linux | Critical | 9.8 | 2026-09-16 10:33:04 | Deep Dive |
| CVE-2026-89972 | nvme: add missing SRCU grace period in error path | Linux | Linux | Critical | 9.8 | 2026-09-16 10:32:52 | Deep Dive |
| CVE-2026-89969 | nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU | Linux | Linux | Critical | 9.8 | 2026-09-16 10:32:50 | Deep Dive |
| CVE-2026-89970 | nvmet-auth: Synchronize timeout work during SQ teardown | Linux | Linux | Critical | 9.8 | 2026-09-16 10:32:50 | Deep Dive |
| CVE-2026-89930 | KVM: nVMX: Service local TLB flushes on failed nested VM-Enter | Linux | Linux | Critical | 9.3 | 2026-09-16 10:32:22 | Deep Dive |
| CVE-2026-89918 | KVM: arm64: Correctly handle end of VA space TLBI invalidation | Linux | Linux | Critical | 9.3 | 2026-09-16 10:32:13 | Deep Dive |
| CVE-2026-89916 | KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry | Linux | Linux | Critical | 9.3 | 2026-09-16 10:32:12 | Deep Dive |
| CVE-2026-89914 | KVM: arm64: Sign-extend VA for range-based TLBI invalidation | Linux | Linux | Critical | 9.3 | 2026-09-16 10:32:11 | Deep Dive |
| CVE-2026-89915 | KVM: arm64: Remove VM-wide VNCR mapping counter | Linux | Linux | Critical | 9.3 | 2026-09-16 10:32:11 | Deep Dive |
| CVE-2026-89857 | scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject | Linux | Linux | Critical | 9.8 | 2026-09-16 10:31:30 | Deep Dive |
| CVE-2026-89847 | scsi: qla2xxx: Avoid double completion in async IOCB timeout | Linux | Linux | Critical | 9.8 | 2026-09-16 10:31:21 | Deep Dive |
| CVE-2026-89846 | scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read | Linux | Linux | Critical | 9.1 | 2026-09-16 10:31:20 | Deep Dive |
| CVE-2026-86106 | Security Advisory 0179 | Arista Networks | VeloCloud Edge | Critical | 9.6 | 2026-09-16 10:12:56 | Deep Dive |
| CVE-2026-73453 | Security Advisory 0174 | Arista Networks | EOS | Critical | 10.0 | 2026-09-16 09:46:34 | Deep Dive |
| CVE-2026-89788 | ksmbd: fix tree connection use-after-free in smb2_tree_connect() | Linux | Linux | Critical | 9.8 | 2026-09-16 08:48:25 | Deep Dive |
| CVE-2026-89786 | ext4: fix out-of-bounds read in ext4_read_inline_dir() | Linux | Linux | Critical | 9.1 | 2026-09-16 08:48:24 | Deep Dive |