Blog
Notes from the KernelScan team
Announcements, deep dives, and the occasional war story from building Linux kernel CVE intelligence.
-
Kernel CVE Batch Analysis: September 24-25, 2026 (606 CVEs, 36 of them remote)
606 Linux kernel CVEs landed on September 24-25, 2026 - 7 Critical, 36 network-reachable Highs, and a new twist: the server is often the attacker.
Read more -
Triaging kernel CVEs on a router nobody patches anymore: a FRITZ!Box 7412 walkthrough
An EOL DSL router on Linux 3.10.73: 20,059 kernel CVEs go in, 595 come out affected, and a config-level triage narrows it to what an attacker can actually reach. Five steps, with KernelScan.
Read more -
Kernel CVE Batch Analysis: September 16-17, 2026 (878 CVEs, 62 of them remote)
878 Linux kernel CVEs landed on September 16-17, 2026 - 37 Critical, but only 62 of the 376 high-rated entries are network-reachable. A product triage.
Read more -
Four Public Root Exploits Dropped Today. We Had the CVEs Since August.
On September 18, working local-root exploits went public for four Linux kernel CVEs. KernelScan had ingested every one of those CVEs on its publication day — and NVD still hasn't scored one of them.
Read more -
Kernel CVE Batch Analysis: September 11, 2026 (431 CVEs, a file-server batch)
431 Linux kernel CVEs landed on September 11, 2026 — 71 Critical, 53 of them in the NFS, Ceph, SMB and OCFS2 file-server stack. A product-triage walkthrough.
Read more -
24 Hours to Report. Unless the Code Isn’t Reachable?
From 11 September 2026 the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities within 24 hours. For Linux-based products, the Commission’s own guidance says an unreachable kernel CVE isn’t reportable — here is what that actually means.
Read more -
BadGarbage (CVE-2026-53361): why product security needs real-time exploit and PoC intelligence
Two public exploits, wrong published version ranges, vendor trackers weeks behind. CVE-2026-53361 as a worked case for why product security needs a real-time source of the latest exploits and PoCs.
Read more -
Exploit Maturity Is Live: Public Kernel PoCs Now Surface in KernelScan
KernelScan now distinguishes public PoCs, weaponized exploits and CISA KEV—and carries both urgency signals into owner-facing CycloneDX VEX exports.
Read more -
Kernel CVE Batch Analysis: August 15, 2026 (848 CVEs, 338 awaiting NVD scores)
848 Linux kernel CVEs landed on August 15. We sort all of them by severity, subsystem, and attacker reachability to expose the product-relevant queue.
Read more -
Kernel CVE Batch Analysis: August 10, 2026 (346 CVEs, none scored by NVD)
A product-focused triage of 346 Linux kernel CVEs published in a single day on August 10, 2026 — every one still unscored by NVD.
Read more -
RefluXFS (CVE-2026-64600): am I actually vulnerable?
A nine-year-old XFS reflink race just became local root on default RHEL. How to decide whether your product is actually affected — from the config symbol, through the USB-stick reflex, to the staggered backport timeline your scanner won’t show you.
Read more -
Kernel CVE Batch Analysis: July 19, 2026 (431 CVEs, none scored by NVD)
A product-focused triage of 431 Linux kernel CVEs published in a single day on July 19, 2026 — none scored by NVD — with a hard look at the ~72 local privilege-escalation bugs, including the keyring, statmount and block-layer ones you can't compile out.
Read more -
Your Scanner Isn’t Wrong. Neither Is NVD. So Why Does It Flag Kernel CVEs You Don’t Have?
We counted: on a fully-patched LTS kernel, up to 46% of scanner-reported kernel CVEs don’t apply to it. Nobody made a mistake — the cause is structural, and verifiable from public data.
Read more -
Introducing the KernelScan Analyzer Plugin for Dependency-Track 5
Our open-source Dependency-Track 5 analyzer plugin surfaces KernelScan's config-aware kernel CVE analysis in DT — only the CVEs reachable in your .config, no NVD noise.
Read more -
CVSS Said 9.8. Your Kernel Config Said “Not Affected.”
Why NVD, Red Hat and a config-based analysis give three different answers for the same June 2026 kernel CVEs — and which one is about your system.
Read more -
Hidden in 219 unscored kernel CVEs: CVE-2026-52943, an 8.4 local root that may not be present in your kernel at all
Buried in 219 kernel CVEs with no NVD scores: a reliable local root in code every kernel ships — yet whether it can touch you comes down to one question the score never answers: is the gating config option, and the module that reaches it, even present in the kernel you run?
Read more -
Kernel CVE Batch Analysis: June 24, 2026 (219 CVEs, none scored by NVD)
A product-focused triage of 219 Linux kernel CVEs published in a single day on June 24, 2026 — every one still unscored by NVD.
Read more -
Kernel CVE Batch Analysis: June 6-9, 2026 (62 CVEs)
A product-focused triage of 62 Linux kernel CVEs published June 6-9, 2026 while NVD scoring is still pending.
Read more -
KernelScan is open — request your invitation code
KernelScan is live in invite-only early access. Here's what we built, why we're ramping up gradually, and how to get your invitation code.
Read more