2026 CVE Vulnerabilities
64,935 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-69559 | MEDIUM | 5.8 | 0.3% | Sep 8, 2026 | Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a netw... |
| CVE-2026-69554 | MEDIUM | 5.5 | 0.3% | Sep 8, 2026 | Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perf... |
| CVE-2026-69552 | MEDIUM | 5.7 | 0.9% | Sep 8, 2026 | Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized at... |
| CVE-2026-69548 | MEDIUM | 4.6 | 0.5% | Sep 8, 2026 | Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical atta... |
| CVE-2026-69531 | MEDIUM | 5.5 | 0.3% | Sep 8, 2026 | Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perfor... |
| CVE-2026-69527 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locall... |
| CVE-2026-69507 | MEDIUM | 5.7 | 0.8% | Sep 8, 2026 | Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component al... |
| CVE-2026-69504 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
| CVE-2026-69497 | MEDIUM | 6.5 | 1.1% | Sep 8, 2026 | Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service ... |
| CVE-2026-69490 | MEDIUM | 6.8 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a... |
| CVE-2026-69483 | MEDIUM | 4.7 | 0.3% | Sep 8, 2026 | Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. |
| CVE-2026-69474 | MEDIUM | 4.8 | 0.7% | Sep 8, 2026 | Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. |
| CVE-2026-69469 | MEDIUM | 6.6 | 0.4% | Sep 8, 2026 | Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to eleva... |
| CVE-2026-69457 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. |
| CVE-2026-69453 | MEDIUM | 5.5 | 0.3% | Sep 8, 2026 | Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. |
| CVE-2026-69449 | MEDIUM | 6.7 | 0.4% | Sep 8, 2026 | Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally. |
| CVE-2026-69425 | MEDIUM | 4.7 | 0.3% | Sep 8, 2026 | Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform ... |
| CVE-2026-69417 | MEDIUM | 5.4 | 0.7% | Sep 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-69416 | MEDIUM | 5.7 | 0.6% | Sep 8, 2026 | Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. |
| CVE-2026-69415 | MEDIUM | 6.8 | 0.7% | Sep 8, 2026 | Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges ... |
| CVE-2026-69409 | MEDIUM | 6.5 | 1.0% | Sep 8, 2026 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose informati... |
| CVE-2026-69406 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attack... |
| CVE-2026-69405 | MEDIUM | 5.7 | 0.6% | Sep 8, 2026 | Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service ... |
| CVE-2026-69403 | MEDIUM | 5.5 | 0.3% | Sep 8, 2026 | Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally. |
| CVE-2026-69402 | MEDIUM | 5.4 | 0.4% | Sep 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now