2026 CVE Vulnerabilities

61,548 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42769MEDIUM5.3Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Mana...
CVE-2026-42768LOW3.7Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacke...
CVE-2026-42767MEDIUM5.9Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer derefere...
CVE-2026-42766MEDIUM5.9Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decr...
CVE-2026-42765HIGH7.5Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the who...
CVE-2026-42764HIGH7.5Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenS...
CVE-2026-42599MEDIUM6.1Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes f...
CVE-2026-42573MEDIUM6.1Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its ...
CVE-2026-42570HIGH7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ...
CVE-2026-42567HIGH7.5Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the S...
CVE-2026-41108HIGH7Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-41098HIGH8.4Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an autho...
CVE-2026-41092HIGH7.8Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
CVE-2026-40409HIGH7.8Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-40404HIGH7.8Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-40376HIGH8.1Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-40371HIGH8.8Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized...
CVE-2026-3088MEDIUM6.5Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted reque...
CVE-2026-38615CRITICAL9.8DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
CVE-2026-35188MEDIUM5Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ...
CVE-2026-34692MEDIUM5.4Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting ...
CVE-2026-34335HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-34183HIGH7.5Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P...
CVE-2026-34182CRITICAL9.1Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe...
CVE-2026-34181HIGH7.4Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now