2026 CVE Vulnerabilities

61,503 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44812HIGH7.8Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
CVE-2026-44811HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-44810HIGH7.8Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.
CVE-2026-44809HIGH7.8Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-44808HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-44807HIGH7.8Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-44805MEDIUM5.5Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.
CVE-2026-44804HIGH7.8Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-44803HIGH7.8Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
CVE-2026-44802HIGH7.8Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-44801HIGH7.5Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-44799HIGH7.5Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42993HIGH7.5Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42992HIGH7.5Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42991HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-42989HIGH7.8Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate priv...
CVE-2026-42987HIGH8.1Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-42986HIGH7.8Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2026-42985HIGH8.8Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42984HIGH7Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-42983HIGH7.8Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-42981HIGH8.1Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code ov...
CVE-2026-42980HIGH7.8Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges local...
CVE-2026-42979HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-42978HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now