2026 CVE Vulnerabilities

64,935 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-80076MEDIUM6.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
CVE-2026-80073MEDIUM6.5Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
CVE-2026-79904MEDIUM5Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulner...
CVE-2026-78522MEDIUM6.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-78520MEDIUM6.5Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-78516MEDIUM4.3Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized ...
CVE-2026-78515MEDIUM6.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-78513MEDIUM5.5Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-78508MEDIUM4.6Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical atta...
CVE-2026-78506MEDIUM5.5Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-78503MEDIUM6.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-78502MEDIUM6.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-78455MEDIUM4.3Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-78454MEDIUM5.5Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
CVE-2026-78453MEDIUM6.5Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to di...
CVE-2026-78452MEDIUM4.6Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information w...
CVE-2026-78451MEDIUM6.8Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate pri...
CVE-2026-78446MEDIUM5.3Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.
CVE-2026-78441MEDIUM6.5Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
CVE-2026-77911MEDIUM6.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-77896MEDIUM6.5Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.
CVE-2026-77892MEDIUM6.8No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical atta...
CVE-2026-77891MEDIUM6.4Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
CVE-2026-77887MEDIUM6.4Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
CVE-2026-77492MEDIUM5.5Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now