2026 CVE Vulnerabilities

45,065 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-58619HIGH7Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58613HIGH7.8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58547HIGH7.8Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges loc...
CVE-2026-58544HIGH7Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-58542HIGH7.8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-58541HIGH7.8Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate pr...
CVE-2026-58540HIGH7.8Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-58539HIGH7.5Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58538HIGH7.8Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58537HIGH7.8Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges loc...
CVE-2026-58536HIGH7.8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58535HIGH7.5Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58534HIGH7.8Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges lo...
CVE-2026-58533HIGH7.5Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58532HIGH7.8Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-58531HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an aut...
CVE-2026-58530HIGH7.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code local...
CVE-2026-58529HIGH7.1Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information...
CVE-2026-58527HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-58277HIGH8.8Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network...
CVE-2026-57968HIGH7.8Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
CVE-2026-57108HIGH7.5Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny servi...
CVE-2026-57102HIGH8.8Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass...
CVE-2026-57096HIGH7.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate ...
CVE-2026-57095HIGH7.8Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now