2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55052 | HIGH | 8.8 | 0.5% | Jul 14, 2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-55049 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-55048 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55045 | HIGH | 8.4 | 0.3% | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-55044 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55043 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2026-55041 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55039 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally... |
| CVE-2026-55038 | HIGH | 7.8 | 0.4% | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-55037 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55036 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55034 | HIGH | 8.7 | 0.6% | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-55033 | HIGH | 7.8 | 0.5% | Jul 14, 2026 | Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-55032 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-55031 | HIGH | 7.8 | 0.4% | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55029 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55025 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ... |
| CVE-2026-55024 | HIGH | 7.8 | 0.4% | Jul 14, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ... |
| CVE-2026-55022 | HIGH | 7.8 | 0.4% | Jul 14, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe... |
| CVE-2026-55021 | HIGH | 8.7 | 0.5% | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-55018 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-55017 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-54131 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-54128 | HIGH | 8.4 | 0.3% | Jul 14, 2026 | Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. |
| CVE-2026-54125 | HIGH | 7.8 | 0.2% | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now