2026 CVE Vulnerabilities

57,986 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58419HIGH7.5Notification API leaks private issue metadata after access revocation
CVE-2026-58418MEDIUM6.5SSRF via HTTP Redirect in Repository Migration
CVE-2026-58300MEDIUM6.2Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-58299HIGH7.5Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execu...
CVE-2026-58298MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ...
CVE-2026-58297HIGH7.1Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a...
CVE-2026-58296HIGH7.1Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a...
CVE-2026-58295HIGH8.3Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-58294HIGH7.5Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-58293HIGH7.5External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code...
CVE-2026-58292HIGH7.5Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw...
CVE-2026-58291MEDIUM6.1Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker t...
CVE-2026-58290HIGH7.5Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-58289HIGH8.3Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-58288HIGH8.3Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-58287HIGH8.3Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-58286MEDIUM6.9Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne...
CVE-2026-58285HIGH8.3Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-58284HIGH8.3Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network...
CVE-2026-58283MEDIUM6.9Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-58282MEDIUM6.9Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne...
CVE-2026-58278MEDIUM5.4Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin...
CVE-2026-58276HIGH7.5Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57993HIGH7.4Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin...
CVE-2026-57992HIGH7.5Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now