2026 CVE Vulnerabilities
64,935 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80076 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-80073 | MEDIUM | 6.5 | 0.9% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-79904 | MEDIUM | 5 | — | Sep 8, 2026 | Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulner... |
| CVE-2026-78522 | MEDIUM | 6.5 | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-78520 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
| CVE-2026-78516 | MEDIUM | 4.3 | 0.5% | Sep 8, 2026 | Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized ... |
| CVE-2026-78515 | MEDIUM | 6.5 | 0.9% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-78513 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. |
| CVE-2026-78508 | MEDIUM | 4.6 | 0.5% | Sep 8, 2026 | Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical atta... |
| CVE-2026-78506 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-78503 | MEDIUM | 6.5 | 0.9% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-78502 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-78455 | MEDIUM | 4.3 | 0.5% | Sep 8, 2026 | Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack. |
| CVE-2026-78454 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally. |
| CVE-2026-78453 | MEDIUM | 6.5 | 0.9% | Sep 8, 2026 | Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to di... |
| CVE-2026-78452 | MEDIUM | 4.6 | 0.5% | Sep 8, 2026 | Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information w... |
| CVE-2026-78451 | MEDIUM | 6.8 | 0.4% | Sep 8, 2026 | Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate pri... |
| CVE-2026-78446 | MEDIUM | 5.3 | 0.8% | Sep 8, 2026 | Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. |
| CVE-2026-78441 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-77911 | MEDIUM | 6.5 | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-77896 | MEDIUM | 6.5 | — | Sep 8, 2026 | Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network. |
| CVE-2026-77892 | MEDIUM | 6.8 | 0.4% | Sep 8, 2026 | No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical atta... |
| CVE-2026-77891 | MEDIUM | 6.4 | 0.3% | Sep 8, 2026 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. |
| CVE-2026-77887 | MEDIUM | 6.4 | 0.3% | Sep 8, 2026 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. |
| CVE-2026-77492 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now