2026 CVE Vulnerabilities

45,066 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-54124HIGH7.8Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
CVE-2026-54121HIGH8.8Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privile...
CVE-2026-54115HIGH7.8Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
CVE-2026-50692HIGH8.8Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-50689HIGH7.8Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
CVE-2026-50688HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50687HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50686HIGH8.1Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute ...
CVE-2026-50685HIGH7.5Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVE-2026-50683HIGH8Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent n...
CVE-2026-50682HIGH7.1Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
CVE-2026-50680HIGH7.8Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2026-50679HIGH7.8Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges loc...
CVE-2026-50677HIGH7.8Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50676HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50674HIGH7.8Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50673HIGH7.8Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50672HIGH7Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50670HIGH7.8Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50669HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service...
CVE-2026-50667HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an au...
CVE-2026-50666HIGH8.8Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a ne...
CVE-2026-50658HIGH7Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privile...
CVE-2026-50655HIGH7.8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-50647HIGH7.5Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now