2026 CVE Vulnerabilities

43,090 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-62798MEDIUM5.5Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62796MEDIUM5.5Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62793MEDIUM5.5Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62786MEDIUM5.5Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62782MEDIUM6.5Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-62775MEDIUM5.5Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to d...
CVE-2026-62769MEDIUM6.7Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62757MEDIUM5.3Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a securit...
CVE-2026-62750MEDIUM6.5Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an ad...
CVE-2026-62746MEDIUM5.5Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62745MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62743MEDIUM5.5Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62742MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62740MEDIUM5.5Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally...
CVE-2026-62738MEDIUM5.5Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
CVE-2026-62730MEDIUM5.5Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
CVE-2026-62720MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62718MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62716MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62715MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62714MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62709MEDIUM5.5Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
CVE-2026-62708MEDIUM6.4Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-62703MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-62702MEDIUM6.8Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now