Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn't log in without the second factor. While that logic was sound, attackers have now figured out that they don't need to steal the second factor: they just need the user to hand it over.
If your workforce authenticates with
A vulnerability was found in Linux Kernel up to 6.12.81/6.18.22/6.19.12. It has been rated as critical. Affected is the function lan966x_fdma_rx_alloc of the component net. Performing a manipulation results in denial of service.
This vulnerability is reported as CVE-2026-31645. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.6.134/6.12.81/6.18.22/6.19.12. This affects the function lan966x_fdma_rx_alloc_page_pool of the component net. The manipulation results in infinite loop.
This vulnerability is known as CVE-2026-31646. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in Linux Kernel up to 6.18.22/6.19.12. It has been classified as critical. This affects the function rxrpc_preparse_xdr_yfs_rxgk of the component rxrpc. This manipulation causes memory leak.
This vulnerability is registered as CVE-2026-31643. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.12.81/6.18.22/6.19.12. It has been declared as critical. This impacts the function lan966x_fdma_reload. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2026-31644. The attack requires being on the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.134/6.12.81/6.18.22/6.19.12. It has been rated as critical. Affected by this issue is the function list_del_rcu. Performing a manipulation results in infinite loop.
This vulnerability is known as CVE-2026-31642. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.18.22/6.19.12. This vulnerability affects the function rxrpc_preparse_xdr_yfs_rxgk. The manipulation leads to time-of-check time-of-use.
This vulnerability is uniquely identified as CVE-2026-31641. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.6.134/6.12.81/6.18.22/6.19.12 and classified as critical. The affected element is the function rxrpc_alloc_client_call of the file /proc/keys. The manipulation leads to improper update of reference count.
This vulnerability is listed as CVE-2026-31639. The attack must be carried out from within the local network. There is no available exploit.
The affected component should be upgraded.
A vulnerability was found in Linux Kernel up to 6.18.22/6.19.12 and classified as critical. The impacted element is the function rxrpc_post_response of the component rxrpc. The manipulation results in incorrect comparison.
This vulnerability is cataloged as CVE-2026-31640. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.134/6.12.81/6.18.22/6.19.12. Impacted is the function rxrpc_input_packet_on_conn. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2026-31638. The attack is only possible within the local network. No exploit exists.
You should upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.22/6.19.12. This issue affects the function rxgk_verify_authenticator of the component rxrpc. This manipulation causes out-of-bounds read.
This vulnerability is tracked as CVE-2026-31636. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.6.134/6.12.81/6.18.22/6.19.12. Impacted is the function rxkad_decrypt_ticket of the component rxrpc. Such manipulation leads to privilege escalation.
This vulnerability is listed as CVE-2026-31637. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability described as critical has been identified in Linux Kernel up to 6.18.22/6.19.12. This vulnerability affects the function rxgk_verify_response of the file scripts/decode_stacktrace.sh of the component rxrpc. The manipulation results in stack-based buffer overflow.
This vulnerability is identified as CVE-2026-31635. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.19.12. This issue affects the function rxrpc_server_keyring of the component rxrpc. Performing a manipulation results in improper update of reference count.
This vulnerability is identified as CVE-2026-31634. The attack can only be performed from the local network. There is not any exploit available.
It is advisable to upgrade the affected component.