2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27914HIGH7.8Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
CVE-2026-27913HIGH7.7Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-27912HIGH8Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
CVE-2026-27911HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Co...
CVE-2026-27910HIGH7.8Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevat...
CVE-2026-27909HIGH7.8Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2026-27908HIGH7Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.
CVE-2026-27907HIGH7.8Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate pri...
CVE-2026-27906MEDIUM4.4Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
CVE-2026-27303CRITICAL9.6Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that ...
CVE-2026-27288MEDIUM5.4Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vuln...
CVE-2026-27258MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2026-27246CRITICAL9.3Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A...
CVE-2026-27245CRITICAL9.3Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. A...
CVE-2026-27243CRITICAL9.3Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. A...
CVE-2026-26184HIGH7.8Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-26183HIGH7.8Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.
CVE-2026-26182HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-26181HIGH7.8Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-26180HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-26179HIGH7.8Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-26178HIGH8.8Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate pri...
CVE-2026-26177HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-26176HIGH7.8Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate priv...
CVE-2026-26175MEDIUM4.6Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now