2026 CVE Vulnerabilities

61,548 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44807HIGH7.8Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-44805MEDIUM5.5Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.
CVE-2026-44804HIGH7.8Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-44803HIGH7.8Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
CVE-2026-44802HIGH7.8Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-44801HIGH7.5Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-44799HIGH7.5Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42993HIGH7.5Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42992HIGH7.5Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42991HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-42989HIGH7.8Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate priv...
CVE-2026-42987HIGH8.1Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-42986HIGH7.8Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2026-42985HIGH8.8Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42984HIGH7Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-42983HIGH7.8Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-42981HIGH8.1Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code ov...
CVE-2026-42980HIGH7.8Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges local...
CVE-2026-42979HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-42978HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-42977HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-42974HIGH8.1Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a net...
CVE-2026-42973MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t...
CVE-2026-42972MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose ...
CVE-2026-42971MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now