2026 CVE Vulnerabilities
64,935 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71348 | MEDIUM | 6.8 | 0.4% | Sep 8, 2026 | Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical atta... |
| CVE-2026-71341 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally. |
| CVE-2026-71339 | MEDIUM | 6.7 | 0.3% | Sep 8, 2026 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
| CVE-2026-71338 | MEDIUM | 6.4 | 0.3% | Sep 8, 2026 | Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally. |
| CVE-2026-71329 | MEDIUM | 6.8 | 0.4% | Sep 8, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
| CVE-2026-70582 | MEDIUM | 6.4 | 0.2% | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instru... |
| CVE-2026-70575 | MEDIUM | 6.5 | 0.8% | Sep 8, 2026 | Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network. |
| CVE-2026-70290 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information lo... |
| CVE-2026-70145 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. |
| CVE-2026-70091 | MEDIUM | 5.9 | 0.7% | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an una... |
| CVE-2026-70019 | MEDIUM | 6.5 | 1.1% | Sep 8, 2026 | Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-69895 | MEDIUM | 4.7 | 0.3% | Sep 8, 2026 | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
| CVE-2026-69878 | MEDIUM | 6.4 | 0.3% | Sep 8, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally. |
| CVE-2026-69874 | MEDIUM | 6.4 | 0.3% | Sep 8, 2026 | Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69862 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information l... |
| CVE-2026-69853 | MEDIUM | 4.7 | 0.3% | Sep 8, 2026 | Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally. |
| CVE-2026-69839 | MEDIUM | 6.5 | 1.1% | Sep 8, 2026 | Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network. |
| CVE-2026-69832 | MEDIUM | 4.7 | 0.4% | Sep 8, 2026 | Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attack... |
| CVE-2026-69820 | MEDIUM | 6.7 | 0.3% | Sep 8, 2026 | Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69808 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
| CVE-2026-69794 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. |
| CVE-2026-69792 | MEDIUM | 4.7 | 0.2% | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an ... |
| CVE-2026-69781 | MEDIUM | 6.5 | 0.5% | Sep 8, 2026 | Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny servic... |
| CVE-2026-69771 | MEDIUM | 4.7 | 0.3% | Sep 8, 2026 | Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized... |
| CVE-2026-69770 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now