2026 CVE Vulnerabilities

43,098 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-62718MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62716MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62715MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62714MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...
CVE-2026-62709MEDIUM5.5Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
CVE-2026-62708MEDIUM6.4Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-62703MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-62702MEDIUM6.8Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
CVE-2026-62699MEDIUM6.8Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to...
CVE-2026-61936MEDIUM5.5Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature lo...
CVE-2026-61933MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-61928MEDIUM5.5Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
CVE-2026-61924MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61921MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61920MEDIUM6.6Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut...
CVE-2026-61918MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61368MEDIUM5Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-61360MEDIUM5.5Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-61350MEDIUM4.6Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-61347MEDIUM5.5Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CVE-2026-61345MEDIUM6.5Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo...
CVE-2026-59138MEDIUM6.5Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo...
CVE-2026-59137MEDIUM5.5Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information loc...
CVE-2026-59136MEDIUM5.5Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally...
CVE-2026-59135MEDIUM5.5Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now