2026 CVE Vulnerabilities

64,935 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-69559MEDIUM5.8Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a netw...
CVE-2026-69554MEDIUM5.5Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perf...
CVE-2026-69552MEDIUM5.7Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized at...
CVE-2026-69548MEDIUM4.6Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical atta...
CVE-2026-69531MEDIUM5.5Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perfor...
CVE-2026-69527MEDIUM5.5Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locall...
CVE-2026-69507MEDIUM5.7Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component al...
CVE-2026-69504MEDIUM5.5Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-69497MEDIUM6.5Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service ...
CVE-2026-69490MEDIUM6.8Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a...
CVE-2026-69483MEDIUM4.7Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally.
CVE-2026-69474MEDIUM4.8Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.
CVE-2026-69469MEDIUM6.6Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to eleva...
CVE-2026-69457MEDIUM5.5Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally.
CVE-2026-69453MEDIUM5.5Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
CVE-2026-69449MEDIUM6.7Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.
CVE-2026-69425MEDIUM4.7Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform ...
CVE-2026-69417MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-69416MEDIUM5.7Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
CVE-2026-69415MEDIUM6.8Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges ...
CVE-2026-69409MEDIUM6.5Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose informati...
CVE-2026-69406MEDIUM5.5Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attack...
CVE-2026-69405MEDIUM5.7Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service ...
CVE-2026-69403MEDIUM5.5Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.
CVE-2026-69402MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now