2026 CVE Vulnerabilities

61,397 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49475HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49472MEDIUM5.3FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49161HIGH7.8Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
CVE-2026-49160HIGH7.5Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
CVE-2026-48583HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-48578HIGH7.9Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
CVE-2026-48576HIGH7.9No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48575HIGH7.9Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48574HIGH7.8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-48573HIGH7.9No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48570HIGH7.9Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48569MEDIUM5.5Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-48568HIGH7.9Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48566MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-48565HIGH7.8Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CVE-2026-48563HIGH7.5Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-48562MEDIUM4.6Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-48560MEDIUM5.4Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over ...
CVE-2026-48304MEDIUM5.4Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XS...
CVE-2026-48301MEDIUM5.4Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XS...
CVE-2026-48300MEDIUM5.4Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XS...
CVE-2026-48299MEDIUM5.4Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XS...
CVE-2026-48297MEDIUM5.4Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XS...
CVE-2026-48289LOW3.5Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln...
CVE-2026-48288LOW3.5Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now