2026 CVE Vulnerabilities
64,935 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-69395 | MEDIUM | 6.5 | 1.0% | Sep 8, 2026 | Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacke... |
| CVE-2026-69393 | MEDIUM | 5.7 | 0.8% | Sep 8, 2026 | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network. |
| CVE-2026-69390 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
| CVE-2026-69382 | MEDIUM | 5.9 | — | Sep 8, 2026 | Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclos... |
| CVE-2026-69381 | MEDIUM | 4.6 | 0.5% | Sep 8, 2026 | Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physica... |
| CVE-2026-69376 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
| CVE-2026-69375 | MEDIUM | 6.5 | 0.6% | Sep 8, 2026 | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform t... |
| CVE-2026-69374 | MEDIUM | 6.5 | 1.1% | Sep 8, 2026 | Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service... |
| CVE-2026-69373 | MEDIUM | 6.7 | 0.4% | Sep 8, 2026 | Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69372 | MEDIUM | 5.7 | 0.9% | Sep 8, 2026 | Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network. |
| CVE-2026-69369 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. |
| CVE-2026-69367 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
| CVE-2026-69361 | MEDIUM | 6.5 | 0.8% | Sep 8, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a... |
| CVE-2026-69353 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. |
| CVE-2026-69351 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host ... |
| CVE-2026-69350 | MEDIUM | 6.7 | 0.4% | Sep 8, 2026 | Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69349 | MEDIUM | 5.7 | 0.9% | Sep 8, 2026 | Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose informatio... |
| CVE-2026-69345 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
| CVE-2026-69344 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
| CVE-2026-69343 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
| CVE-2026-69339 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an auth... |
| CVE-2026-69321 | MEDIUM | 5.5 | 0.3% | Sep 8, 2026 | Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to pe... |
| CVE-2026-69318 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. |
| CVE-2026-69317 | MEDIUM | 5.7 | 0.9% | Sep 8, 2026 | Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. |
| CVE-2026-69316 | MEDIUM | 4.7 | 0.3% | Sep 8, 2026 | Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now