2026 CVE Vulnerabilities

64,935 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-71348MEDIUM6.8Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical atta...
CVE-2026-71341MEDIUM5.5Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.
CVE-2026-71339MEDIUM6.7Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-71338MEDIUM6.4Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
CVE-2026-71329MEDIUM6.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-70582MEDIUM6.4Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instru...
CVE-2026-70575MEDIUM6.5Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.
CVE-2026-70290MEDIUM5.5Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information lo...
CVE-2026-70145MEDIUM5.5Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CVE-2026-70091MEDIUM5.9Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an una...
CVE-2026-70019MEDIUM6.5Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.
CVE-2026-69895MEDIUM4.7Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
CVE-2026-69878MEDIUM6.4Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally.
CVE-2026-69874MEDIUM6.4Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-69862MEDIUM5.5Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information l...
CVE-2026-69853MEDIUM4.7Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-69839MEDIUM6.5Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
CVE-2026-69832MEDIUM4.7Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attack...
CVE-2026-69820MEDIUM6.7Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
CVE-2026-69808MEDIUM5.5Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-69794MEDIUM5.5Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
CVE-2026-69792MEDIUM4.7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an ...
CVE-2026-69781MEDIUM6.5Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny servic...
CVE-2026-69771MEDIUM4.7Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized...
CVE-2026-69770MEDIUM5.5Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now