2026 CVE Vulnerabilities

43,877 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-50668MEDIUM6.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-50661MEDIUM4.6Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph...
CVE-2026-50657MEDIUM5.5Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to...
CVE-2026-50495MEDIUM5.5Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
CVE-2026-50492MEDIUM6.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with ...
CVE-2026-50485MEDIUM5.7Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2026-50483MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker...
CVE-2026-50475MEDIUM5.5Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50473MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-50468MEDIUM6.5Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-50456MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-50455MEDIUM5.5Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose informatio...
CVE-2026-50453MEDIUM4.6Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat...
CVE-2026-50442MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-50437MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-50434MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t...
CVE-2026-50432MEDIUM6.5Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
CVE-2026-50431MEDIUM5.5Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
CVE-2026-50430MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t...
CVE-2026-50428MEDIUM5.5Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclo...
CVE-2026-50426MEDIUM6.8Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
CVE-2026-50420MEDIUM5.5Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.
CVE-2026-50418MEDIUM6.1Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-50409MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to di...
CVE-2026-50408MEDIUM5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now