In his first appearance before the panel since being confirmed in March, Mullin said that CISA probably needs “somewhere around” 2,800 employees, despite its ability to hire up to 3,400.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.19.3. This vulnerability affects unknown code of the component octeontx2-af. This manipulation causes denial of service.
This vulnerability appears as CVE-2026-46249. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.18.13/6.19.3. This affects the function ath12k_mac_op_change_vif_links of the file drivers/net/wireless/ath/ath12k/mac.c of the component wifi. The manipulation of the argument links_map results in improper initialization.
This vulnerability is reported as CVE-2026-46248. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Linux Kernel up to 6.12.74/6.18.13/6.19.3. Affected by this issue is the function extcon_set_state_sync of the component power. The manipulation leads to use after free.
This vulnerability is documented as CVE-2026-46246. The attack requires being on the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.19.3. Affected by this vulnerability is the function alloc_workqueue of the component PCI. Executing a manipulation can lead to null pointer dereference.
This vulnerability is registered as CVE-2025-71313. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.13/6.19.3. Affected is the function p2pmem_alloc_mmap of the component P2PDMA. Performing a manipulation results in improper update of reference count.
This vulnerability is cataloged as CVE-2026-46268. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.164/6.6.127/6.12.74/6.18.13/6.19.3. This impacts an unknown function of the component hns. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-46265. The attack must be carried out from within the local network. There is no available exploit.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.74/6.18.13/6.19.3. This affects the function ARRAY_SIZE of the file drm/amd/display. This manipulation causes out-of-bounds read.
This vulnerability is tracked as CVE-2026-46263. The attack is only possible within the local network. No exploit exists.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.127/6.12.74/6.18.13/6.19.3. The impacted element is the function wpcm_fiu_probe of the component spi. The manipulation of the argument memory_size results in null pointer dereference.
This vulnerability is identified as CVE-2026-46261. The attack can only be performed from the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
A disabled security setting meant to protect authentication across Android versions of key apps like Word, PowerPoint, and Excel paved the way for attackers to steal logins and data.
A vulnerability was found in Linux Kernel up to 6.19.3 on ARM32. It has been rated as critical. The affected element is the function read_current_timer of the file clocksource/drivers/timer-sp804 of the component clocksource. The manipulation leads to uninitialized pointer.
This vulnerability is referenced as CVE-2026-46257. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in Linux Kernel up to 6.6.127/6.12.74/6.18.13/6.19.3. It has been declared as critical. Impacted is the function remove of the file drivers/clk/clk.c of the component dmaengine. Executing a manipulation can lead to allocation of resources.
The identification of this vulnerability is CVE-2026-46255. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.74/6.18.13/6.19.3. It has been classified as critical. This issue affects the function get_unaligned_xx of the file security/apparmor/match.c of the component AppArmor. Performing a manipulation results in stack-based buffer overflow.
This vulnerability was named CVE-2026-46254. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.19.3 and classified as critical. This vulnerability affects the function relocate_kernel of the component MIPS. Such manipulation of the argument gp leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-46250. The attack can only be initiated within the local network. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.19.3 and classified as critical. This affects the function regulator_resolve_supply of the file drivers/regulator/core.c of the component regulator. This manipulation causes improper locking.
This vulnerability is handled as CVE-2026-46252. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in OP-TEE optee_os up to 4.10.x. Affected by this issue is the function sp_mem_remove. The manipulation of the argument receivers results in use after free.
This vulnerability is known as CVE-2026-40290. Attacking locally is a requirement. No exploit is available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.164/6.6.127/6.12.74/6.18.13/6.19.3. Affected by this vulnerability is the function list_add_tail of the component btrfs. The manipulation of the argument dirty_list leads to improper synchronization.
This vulnerability is traded as CVE-2026-46251. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.1.164/6.6.127/6.12.74/6.18.13/6.19.3. Affected is the function round_rate of the file drivers/clk/clk.c of the component clk. Executing a manipulation can lead to denial of service.
This vulnerability appears as CVE-2026-46247. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Cisco Finesse. This impacts an unknown function of the component Link Handler. Performing a manipulation results in file inclusion.
This vulnerability is reported as CVE-2026-20175. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.