2026 CVE Vulnerabilities
43,869 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62656 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requ... |
| CVE-2026-62655 | MEDIUM | 5.7 | 0.2% | Jul 14, 2026 | A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to st... |
| CVE-2026-58638 | MEDIUM | 5.5 | 0.2% | Jul 14, 2026 | Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. |
| CVE-2026-58546 | MEDIUM | 6.5 | 0.5% | Jul 14, 2026 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-58545 | MEDIUM | 5.5 | 0.2% | Jul 14, 2026 | Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
| CVE-2026-58543 | MEDIUM | 6.3 | 0.2% | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver ... |
| CVE-2026-58528 | MEDIUM | 4.6 | 0.5% | Jul 14, 2026 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat... |
| CVE-2026-57982 | MEDIUM | 6.5 | 1.0% | Jul 14, 2026 | Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. |
| CVE-2026-57973 | MEDIUM | 4.7 | 0.2% | Jul 14, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perfor... |
| CVE-2026-57101 | MEDIUM | 6.1 | 0.4% | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una... |
| CVE-2026-57084 | MEDIUM | 5.5 | 0.5% | Jul 14, 2026 | Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. |
| CVE-2026-57083 | MEDIUM | 5.5 | 0.5% | Jul 14, 2026 | Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose informatio... |
| CVE-2026-56195 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-56192 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-56186 | MEDIUM | 6.5 | 1.1% | Jul 14, 2026 | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. |
| CVE-2026-56184 | MEDIUM | 5.5 | 0.5% | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose i... |
| CVE-2026-56168 | MEDIUM | 6.5 | 0.8% | Jul 14, 2026 | Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. |
| CVE-2026-56157 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-55142 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55138 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55135 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-55126 | MEDIUM | 5.4 | 0.5% | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-55124 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose info... |
| CVE-2026-55121 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55057 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now