freenode
Desktop & Graphics

X.Org X server patches dozen CVEs in October 2026 batch

Twelve security fixes land together for the reference X window system server used across Linux and Unix desktops.

The X.Org X server has shipped a consolidated set of fixes for twelve security vulnerabilities, published as an October 2026 batch on freedesktop.org GitLab.

The issues are tracked as CVE-2026-88812, CVE-2026-93515, CVE-2026-93516, CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, and CVE-2026-93536. Maintainers directed integrators to the individual fix commits for technical detail.

The X server remains the core display server for many Linux and BSD desktop stacks, so unpatched flaws there can expose local users and multi-seat or remote-X deployments. Distributions that package xorg-server are expected to pick up the batch for their next security updates.