2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49797 | HIGH | 7.8 | 0.4% | Jul 14, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
| CVE-2026-49796 | HIGH | 7.8 | 0.4% | Jul 14, 2026 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
| CVE-2026-49795 | HIGH | 8.8 | 1.9% | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2026-49793 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally... |
| CVE-2026-49792 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
| CVE-2026-49791 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow... |
| CVE-2026-49790 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-49789 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
| CVE-2026-49788 | HIGH | 7.5 | 0.8% | Jul 14, 2026 | Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a ne... |
| CVE-2026-49787 | HIGH | 7.5 | 0.8% | Jul 14, 2026 | Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service... |
| CVE-2026-49784 | HIGH | 7 | 0.2% | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Sto... |
| CVE-2026-49783 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a secu... |
| CVE-2026-49184 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
| CVE-2026-49183 | HIGH | 7 | 0.2% | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server ... |
| CVE-2026-49178 | HIGH | 8.8 | 0.6% | Jul 14, 2026 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a netw... |
| CVE-2026-49176 | HIGH | 7.8 | 0.2% | Jul 14, 2026 | Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. |
| CVE-2026-49175 | HIGH | 7.8 | 0.2% | Jul 14, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
| CVE-2026-49173 | HIGH | 7.8 | 0.2% | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2026-49171 | HIGH | 7.8 | 0.2% | Jul 14, 2026 | Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
| CVE-2026-49170 | HIGH | 7.8 | 2.8% | Jul 14, 2026 | Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privi... |
| CVE-2026-49169 | HIGH | 8.8 | 0.5% | Jul 14, 2026 | Use after free in DNS Server allows an authorized attacker to execute code over a network. |
| CVE-2026-49167 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2026-49166 | HIGH | 7.8 | 0.2% | Jul 14, 2026 | Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. |
| CVE-2026-49165 | HIGH | 7.1 | 0.2% | Jul 14, 2026 | Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information local... |
| CVE-2026-49162 | HIGH | 7 | 0.2% | Jul 14, 2026 | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now