2026 CVE Vulnerabilities
43,098 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62718 | MEDIUM | 6.5 | — | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov... |
| CVE-2026-62716 | MEDIUM | 6.5 | — | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov... |
| CVE-2026-62715 | MEDIUM | 6.5 | 0.5% | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov... |
| CVE-2026-62714 | MEDIUM | 6.5 | — | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov... |
| CVE-2026-62709 | MEDIUM | 5.5 | — | Aug 11, 2026 | Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
| CVE-2026-62708 | MEDIUM | 6.4 | — | Aug 11, 2026 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. |
| CVE-2026-62703 | MEDIUM | 5.5 | 0.4% | Aug 11, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
| CVE-2026-62702 | MEDIUM | 6.8 | — | Aug 11, 2026 | Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. |
| CVE-2026-62699 | MEDIUM | 6.8 | 0.4% | Aug 11, 2026 | Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to... |
| CVE-2026-61936 | MEDIUM | 5.5 | 0.3% | Aug 11, 2026 | Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature lo... |
| CVE-2026-61933 | MEDIUM | 5.5 | — | Aug 11, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
| CVE-2026-61928 | MEDIUM | 5.5 | — | Aug 11, 2026 | Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. |
| CVE-2026-61924 | MEDIUM | 6.5 | 0.8% | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-61921 | MEDIUM | 6.5 | — | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-61920 | MEDIUM | 6.6 | — | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut... |
| CVE-2026-61918 | MEDIUM | 6.5 | — | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-61368 | MEDIUM | 5 | 0.5% | Aug 11, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. |
| CVE-2026-61360 | MEDIUM | 5.5 | — | Aug 11, 2026 | Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. |
| CVE-2026-61350 | MEDIUM | 4.6 | 0.5% | Aug 11, 2026 | Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. |
| CVE-2026-61347 | MEDIUM | 5.5 | — | Aug 11, 2026 | Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
| CVE-2026-61345 | MEDIUM | 6.5 | 1.0% | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo... |
| CVE-2026-59138 | MEDIUM | 6.5 | 1.0% | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo... |
| CVE-2026-59137 | MEDIUM | 5.5 | 0.4% | Aug 11, 2026 | Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information loc... |
| CVE-2026-59136 | MEDIUM | 5.5 | 0.4% | Aug 11, 2026 | Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally... |
| CVE-2026-59135 | MEDIUM | 5.5 | 0.3% | Aug 11, 2026 | Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now