2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40398HIGH7.8Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
CVE-2026-40397HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2026-40382HIGH7.8Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-40381HIGH7.8Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-40380MEDIUM6.2Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physi...
CVE-2026-40379HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform ...
CVE-2026-40377HIGH7.8Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally...
CVE-2026-40374MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose i...
CVE-2026-40370HIGH8.8External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-40369HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-40368HIGH8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-40367HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40366HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40365HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-40364HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40363HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40362HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40361HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40360HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-40359HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40358HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40357HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-35440MEDIUM5.5Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose...
CVE-2026-35439HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-35438HIGH8.3Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now