2026 CVE Vulnerabilities

45,066 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-50438HIGH8.8Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to ...
CVE-2026-50436HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50435HIGH7.8Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
CVE-2026-50433HIGH7.8Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50429HIGH8.2Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
CVE-2026-50427HIGH7.8Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-50425HIGH7.8Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
CVE-2026-50424HIGH7.5Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a networ...
CVE-2026-50423HIGH7.8Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50422HIGH7.8Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50421HIGH7.8Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows...
CVE-2026-50417HIGH7.8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50415HIGH7.5Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose ...
CVE-2026-50414HIGH8.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50413HIGH7.8Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50412HIGH7.8Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50411HIGH7.5Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv...
CVE-2026-50410HIGH7Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50407HIGH7.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges l...
CVE-2026-50406HIGH7.8Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
CVE-2026-50405HIGH7.8Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate ...
CVE-2026-50404HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50403HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-50402HIGH7.8Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50400HIGH7.8Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now