2026 CVE Vulnerabilities
43,188 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61936 | MEDIUM | 5.5 | 0.3% | Aug 11, 2026 | Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature lo... |
| CVE-2026-61933 | MEDIUM | 5.5 | — | Aug 11, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
| CVE-2026-61928 | MEDIUM | 5.5 | — | Aug 11, 2026 | Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. |
| CVE-2026-61924 | MEDIUM | 6.5 | 0.8% | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-61921 | MEDIUM | 6.5 | — | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-61920 | MEDIUM | 6.6 | — | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut... |
| CVE-2026-61918 | MEDIUM | 6.5 | — | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-61368 | MEDIUM | 5 | 0.5% | Aug 11, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. |
| CVE-2026-61360 | MEDIUM | 5.5 | — | Aug 11, 2026 | Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. |
| CVE-2026-61350 | MEDIUM | 4.6 | 0.5% | Aug 11, 2026 | Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. |
| CVE-2026-61347 | MEDIUM | 5.5 | — | Aug 11, 2026 | Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
| CVE-2026-61345 | MEDIUM | 6.5 | 1.0% | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo... |
| CVE-2026-59138 | MEDIUM | 6.5 | 1.0% | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo... |
| CVE-2026-59137 | MEDIUM | 5.5 | 0.4% | Aug 11, 2026 | Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information loc... |
| CVE-2026-59136 | MEDIUM | 5.5 | 0.4% | Aug 11, 2026 | Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally... |
| CVE-2026-59135 | MEDIUM | 5.5 | 0.3% | Aug 11, 2026 | Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. |
| CVE-2026-59131 | MEDIUM | 5.6 | 0.3% | Aug 11, 2026 | No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
| CVE-2026-59130 | MEDIUM | 5.6 | 0.3% | Aug 11, 2026 | No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
| CVE-2026-59128 | MEDIUM | 5.5 | 0.4% | Aug 11, 2026 | Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally... |
| CVE-2026-58639 | MEDIUM | 6.5 | 0.8% | Aug 11, 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over... |
| CVE-2026-57105 | MEDIUM | 5.4 | — | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-54123 | MEDIUM | 5.5 | — | Aug 11, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attac... |
| CVE-2026-48483 | MEDIUM | 5.4 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp... |
| CVE-2026-48446 | MEDIUM | 5.5 | 0.2% | Aug 11, 2026 | CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')... |
| CVE-2026-48445 | MEDIUM | 6.2 | — | Aug 11, 2026 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now