2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-69318 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. |
| CVE-2026-69317 | MEDIUM | 5.7 | 0.9% | Sep 8, 2026 | Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. |
| CVE-2026-69316 | MEDIUM | 4.7 | 0.3% | Sep 8, 2026 | Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
| CVE-2026-69315 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authoriz... |
| CVE-2026-69308 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
| CVE-2026-69304 | MEDIUM | 5.9 | — | Sep 8, 2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny... |
| CVE-2026-69303 | MEDIUM | 5.5 | — | Sep 8, 2026 | Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. |
| CVE-2026-69297 | MEDIUM | 6.5 | 0.8% | Sep 8, 2026 | Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information o... |
| CVE-2026-69294 | MEDIUM | 5.5 | 0.3% | Sep 8, 2026 | Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker ... |
| CVE-2026-69288 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
| CVE-2026-69286 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose informatio... |
| CVE-2026-69267 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized atta... |
| CVE-2026-68898 | MEDIUM | 6.5 | 0.9% | Sep 8, 2026 | Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. |
| CVE-2026-68895 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally. |
| CVE-2026-68891 | MEDIUM | 4.7 | 0.3% | Sep 8, 2026 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
| CVE-2026-68886 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. |
| CVE-2026-68881 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
| CVE-2026-68874 | MEDIUM | 5.7 | 0.9% | Sep 8, 2026 | Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose informat... |
| CVE-2026-68873 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized... |
| CVE-2026-68852 | MEDIUM | 5.5 | 0.5% | Sep 8, 2026 | Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. |
| CVE-2026-68851 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
| CVE-2026-68849 | MEDIUM | 4.7 | 0.2% | Sep 8, 2026 | Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally. |
| CVE-2026-68843 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. |
| CVE-2026-68842 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an auth... |
| CVE-2026-68833 | MEDIUM | 6.8 | 0.4% | Sep 8, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now