2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-64904HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe...
CVE-2026-64903HIGH7.8Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64901HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-64898HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63533HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63532HIGH7.8Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63527HIGH7.8Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-63526HIGH7.8Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63525HIGH7.8Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-63522HIGH7.8Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate pri...
CVE-2026-63520HIGH8.1Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-63519HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63518HIGH7.8Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-63515HIGH7.8Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63514HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-63513HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-62914HIGH7.3Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows...
CVE-2026-62913HIGH8.8Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62911HIGH8Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges...
CVE-2026-62910HIGH7.2Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attack...
CVE-2026-62909HIGH7.8Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62908HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all...
CVE-2026-62901HIGH7.5Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62898HIGH7.5Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62897HIGH7Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now