2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45204MEDIUM5.5Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kern...
CVE-2026-45198HIGH7.8Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause G...
CVE-2026-19189HIGH7.8A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functional...
CVE-2026-70332CRITICAL9.6Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-68823CRITICAL9.1Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n...
CVE-2026-65668HIGH8.8Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo...
CVE-2026-65667CRITICAL10Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-63508CRITICAL10Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev...
CVE-2026-62918HIGH7.5Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing ...
CVE-2026-62896CRITICAL9.6Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2026-62873CRITICAL9.8Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat...
CVE-2026-62836CRITICAL10Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized...
CVE-2026-62830CRITICAL9.9Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-59118CRITICAL9.3Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-59115CRITICAL9.9'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges ove...
CVE-2026-56162CRITICAL10Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56161CRITICAL9.6Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVE-2026-50515CRITICAL9.9Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVE-2026-50481CRITICAL9.9Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privile...
CVE-2026-49163HIGH8.8Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a...
CVE-2026-17264MEDIUM5.3Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of...
CVE-2026-15805Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8325HIGH7.8A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A ma...
CVE-2026-7867HIGH7.8A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization chec...
CVE-2026-7406HIGH7.8A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now