2026 CVE Vulnerabilities

64,935 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-69395MEDIUM6.5Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacke...
CVE-2026-69393MEDIUM5.7Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network.
CVE-2026-69390MEDIUM5.5Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
CVE-2026-69382MEDIUM5.9Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclos...
CVE-2026-69381MEDIUM4.6Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physica...
CVE-2026-69376MEDIUM5.5Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-69375MEDIUM6.5Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform t...
CVE-2026-69374MEDIUM6.5Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service...
CVE-2026-69373MEDIUM6.7Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
CVE-2026-69372MEDIUM5.7Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network.
CVE-2026-69369MEDIUM5.5Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally.
CVE-2026-69367MEDIUM5.5Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-69361MEDIUM6.5Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a...
CVE-2026-69353MEDIUM5.5Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally.
CVE-2026-69351MEDIUM5.5Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host ...
CVE-2026-69350MEDIUM6.7Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
CVE-2026-69349MEDIUM5.7Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose informatio...
CVE-2026-69345MEDIUM5.5Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-69344MEDIUM5.5Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVE-2026-69343MEDIUM5.5Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
CVE-2026-69339MEDIUM5.5Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an auth...
CVE-2026-69321MEDIUM5.5Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to pe...
CVE-2026-69318MEDIUM5.5Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally.
CVE-2026-69317MEDIUM5.7Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.
CVE-2026-69316MEDIUM4.7Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now