2026 CVE Vulnerabilities

43,188 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-65782HIGH7Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65781HIGH7Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65780HIGH7Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65779HIGH7Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65778HIGH7Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65776HIGH7Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-65775HIGH7.8Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-65774HIGH7.8Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-65773HIGH7.8Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-65768HIGH8.8Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an ...
CVE-2026-65767HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allo...
CVE-2026-65681HIGH7.5Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.
CVE-2026-65679HIGH8.1Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ...
CVE-2026-65678HIGH7Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-65675HIGH7.1No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security ...
CVE-2026-65673HIGH7.8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync all...
CVE-2026-65672HIGH7.8Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-65671HIGH7.8Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-65665HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-65664HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65663HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-65661HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65658HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-65657HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65656HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now