Affects the Linux kernel iSCSI target (widely deployed); remote kernel compromise or DoS can disrupt enterprise infrastructure.
CVE-2026-63887
Heap overflow in Linux iSCSI target during login allows remote kernel compromise.
Is CVE-2026-63887 being exploited?
Not confirmed. CVE-2026-63887 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.78% probability of exploitation in the next 30 days.
How severe is CVE-2026-63887?
CVE-2026-63887 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63887?
Yes. A fix has been recorded for CVE-2026-63887. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63887 affect?
CVE-2026-63887 affects Linux kernel (iscsit iSCSI target module), Distributions with iscsit enabled. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63887?
Apply vendor/kernel security updates or disable iSCSI target (iscsit) until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote iSCSI initiator can trigger a heap overflow during login, enabling remote kernel memory corruption leading to RCE or system crash (DoS).
Immediate action required
- affected>= e48354ce078c079996f89d715dfa44814b4eba01 and < cb84e974fb172bc71386289f37b78ea679410b39
- affected>= e48354ce078c079996f89d715dfa44814b4eba01 and < b19382dfc6e7dee6d3859ba44b6ca29e97a51627
- affected>= e48354ce078c079996f89d715dfa44814b4eba01 and < efe633e600a0ac68357206fede21b1ac8178f3b8
- affected>= e48354ce078c079996f89d715dfa44814b4eba01 and < 4e9f0c4a645c995bc75c06c7b3644254ffb4c76b
- affected>= e48354ce078c079996f89d715dfa44814b4eba01 and < 30bf335e8fe170322080ee001f05ca29c50680b3
- affected>= e48354ce078c079996f89d715dfa44814b4eba01 and < 594a40360012ce5f94c715d5e3b20fa3af7d525a
- affected>= e48354ce078c079996f89d715dfa44814b4eba01 and < 26e4a304b7e6f1338c675d527608d32549c091db
- affected>= e48354ce078c079996f89d715dfa44814b4eba01 and < bf33e01f88388c43e285492a63e539df6ffed64c
- affected3.1
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.