CVE Weekly Report — Week of Jun 22 – June 28, 2026
2026-W26
58
Total CVEs
1
Critical
17
High
0
Actively exploited
🔴 Critical CVEs (35)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-53176 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADE… | Jun 25 |
| CVE-2026-52986 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strto… | Jun 24 |
| CVE-2026-52958 | Linux | 9.1 | — | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdm… | Jun 24 |
| CVE-2026-52982 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_st… | Jun 24 |
| CVE-2026-53046 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qual… | Jun 24 |
| CVE-2026-53224 | Linux | 9.1 | — | In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list… | Jun 25 |
| CVE-2026-53045 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The cod… | Jun 24 |
| CVE-2026-53228 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offlo… | Jun 25 |
| CVE-2026-53221 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_… | Jun 25 |
| CVE-2026-53225 | Linux | 9.1 | — | In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup(… | Jun 25 |
| CVE-2026-53043 | Linux | 9.1 | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regi… | Jun 24 |
| CVE-2026-52999 | Linux | 9.1 | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on… | Jun 24 |
| CVE-2026-53186 | Linux | 9.1 | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received … | Jun 25 |
| CVE-2026-52914 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounti… | Jun 24 |
| CVE-2026-53215 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use… | Jun 25 |
| CVE-2026-53216 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer … | Jun 25 |
| CVE-2026-53247 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in m… | Jun 25 |
| CVE-2026-53151 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table… | Jun 25 |
| CVE-2026-53246 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COO… | Jun 25 |
| CVE-2026-53010 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durab… | Jun 24 |
| CVE-2026-53055 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-fre… | Jun 24 |
| CVE-2026-53131 | Linux | 9.4 | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using… | Jun 25 |
| CVE-2026-53088 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb … | Jun 24 |
| CVE-2026-53309 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() re… | Jun 26 |
| CVE-2026-52931 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender va… | Jun 24 |
| CVE-2026-53006 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching sad… | Jun 24 |
| CVE-2026-53049 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_l… | Jun 24 |
| CVE-2026-52955 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crus… | Jun 24 |
| CVE-2026-53260 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk… | Jun 25 |
| CVE-2026-52993 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_ms… | Jun 24 |
| CVE-2026-52989 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() er… | Jun 24 |
| CVE-2026-53002 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace… | Jun 24 |
| CVE-2026-52924 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling … | Jun 24 |
| CVE-2026-53175 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir… | Jun 25 |
| CVE-2026-53086 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmg… | Jun 24 |
🟠 High CVEs (0)
No CVEs in this category this week.
