2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-68831 | MEDIUM | 5.5 | 0.6% | Sep 8, 2026 | Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker t... |
| CVE-2026-68830 | MEDIUM | 5.5 | 0.4% | Sep 8, 2026 | Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host all... |
| CVE-2026-68785 | MEDIUM | 4.9 | 0.8% | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-68784 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68781 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68780 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68779 | MEDIUM | 6.5 | 0.6% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68778 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68777 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68776 | MEDIUM | 6.5 | 0.6% | Sep 8, 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67648 | MEDIUM | 6.5 | 0.6% | Sep 8, 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67645 | MEDIUM | 6.5 | 0.6% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67641 | MEDIUM | 6.5 | 0.6% | Sep 8, 2026 | Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network. |
| CVE-2026-67633 | MEDIUM | 6.5 | 0.8% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. |
| CVE-2026-67630 | MEDIUM | 6.5 | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67629 | MEDIUM | 6.5 | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67624 | MEDIUM | 6.5 | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67393 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67390 | MEDIUM | 6.5 | 1.0% | Sep 8, 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67389 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67386 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67383 | MEDIUM | 6.5 | 1.0% | Sep 8, 2026 | Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose inf... |
| CVE-2026-67369 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-66816 | MEDIUM | 6.5 | 0.7% | Sep 8, 2026 | Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network. |
| CVE-2026-65812 | MEDIUM | 6.8 | 0.5% | Sep 8, 2026 | Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now