2026 CVE Vulnerabilities
64,922 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66308 | MEDIUM | 6.5 | 0.6% | Sep 8, 2026 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. |
| CVE-2026-66306 | MEDIUM | 6.5 | 0.5% | Sep 8, 2026 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to di... |
| CVE-2026-66303 | MEDIUM | 6.5 | 0.8% | Sep 8, 2026 | Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. |
| CVE-2026-63523 | MEDIUM | 6.1 | 0.7% | Sep 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an una... |
| CVE-2026-55256 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation... |
| CVE-2026-45527 | MEDIUM | 4.3 | 0.3% | Sep 8, 2026 | In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service d... |
| CVE-2026-28633 | MEDIUM | 5.5 | 0.1% | Sep 8, 2026 | In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to ... |
| CVE-2026-28627 | MEDIUM | 4.3 | 0.2% | Sep 8, 2026 | In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This cou... |
| CVE-2026-28617 | MEDIUM | 5.5 | 0.1% | Sep 8, 2026 | In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could ... |
| CVE-2026-28596 | MEDIUM | 5.5 | 0.1% | Sep 8, 2026 | In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource ... |
| CVE-2026-28584 | MEDIUM | 5.5 | 0.1% | Sep 8, 2026 | In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a... |
| CVE-2026-9215 | MEDIUM | 6.7 | 0.1% | Sep 8, 2026 | A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage socia... |
| CVE-2026-86672 | MEDIUM | 5.3 | 0.3% | Sep 8, 2026 | A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. A... |
| CVE-2026-85875 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-83991 | MEDIUM | 5.5 | 0.3% | Sep 8, 2026 | Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to ... |
| CVE-2026-83951 | MEDIUM | 5.5 | — | Sep 8, 2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-83949 | MEDIUM | 5.5 | — | Sep 8, 2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-83501 | MEDIUM | 5.5 | 0.3% | Sep 8, 2026 | Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose info... |
| CVE-2026-81958 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81824 | MEDIUM | 4.7 | 0.2% | Sep 8, 2026 | The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMB... |
| CVE-2026-81823 | MEDIUM | 5.3 | 0.2% | Sep 8, 2026 | The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for P... |
| CVE-2026-81401 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ... |
| CVE-2026-81400 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81399 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81395 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now