2026 CVE Vulnerabilities

43,872 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-55121MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55057MEDIUM5.5Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55054MEDIUM6.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-55051MEDIUM6.5Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information ...
CVE-2026-55050MEDIUM5.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-55047MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55046MEDIUM5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55042MEDIUM5.5Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55030MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-55028MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55027MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55026MEDIUM5.5Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55023MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55020MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-55019MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-55016MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-54126MEDIUM6.5Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-54116MEDIUM6.5Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose in...
CVE-2026-50690MEDIUM5.5Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVE-2026-50684MEDIUM4.8Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Serv...
CVE-2026-50681MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack...
CVE-2026-50668MEDIUM6.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-50661MEDIUM4.6Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph...
CVE-2026-50657MEDIUM5.5Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to...
CVE-2026-50495MEDIUM5.5Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now