2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26162 | HIGH | 7.8 | 0.3% | Apr 14, 2026 | Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate pr... |
| CVE-2026-26161 | HIGH | 7.8 | 0.3% | Apr 14, 2026 | Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally... |
| CVE-2026-26160 | HIGH | 7.8 | 0.3% | Apr 14, 2026 | Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker t... |
| CVE-2026-26159 | HIGH | 7.8 | 0.3% | Apr 14, 2026 | Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker t... |
| CVE-2026-26156 | HIGH | 7.8 | 0.4% | Apr 14, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally. |
| CVE-2026-26155 | MEDIUM | 6.5 | 0.9% | Apr 14, 2026 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
| CVE-2026-26154 | HIGH | 7.5 | 1.1% | Apr 14, 2026 | Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a n... |
| CVE-2026-26153 | HIGH | 7.8 | 0.3% | Apr 14, 2026 | Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. |
| CVE-2026-26152 | HIGH | 7 | 0.2% | Apr 14, 2026 | Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate pri... |
| CVE-2026-26151 | HIGH | 7.1 | 0.8% | Apr 14, 2026 | Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spo... |
| CVE-2026-26149 | CRITICAL | 9 | 0.6% | Apr 14, 2026 | Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to p... |
| CVE-2026-26143 | HIGH | 7.8 | 0.5% | Apr 14, 2026 | Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2026-25184 | HIGH | 7 | 0.2% | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (... |
| CVE-2026-24907 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cros... |
| CVE-2026-24906 | MEDIUM | 5.4 | 0.3% | Apr 14, 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cros... |
| CVE-2026-23670 | MEDIUM | 5.7 | 0.3% | Apr 14, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to by... |
| CVE-2026-23666 | HIGH | 7.5 | 1.3% | Apr 14, 2026 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-23657 | HIGH | 7.8 | 0.4% | Apr 14, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-23653 | MEDIUM | 6.5 | 0.7% | Apr 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio ... |
| CVE-2026-21331 | MEDIUM | 6.1 | 0.3% | Apr 14, 2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. I... |
| CVE-2026-20945 | MEDIUM | 5.4 | 25.1% | Apr 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-20930 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic... |
| CVE-2026-20928 | MEDIUM | 4.6 | 0.4% | Apr 14, 2026 | Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an una... |
| CVE-2026-20806 | MEDIUM | 5.5 | 0.3% | Apr 14, 2026 | Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose i... |
| CVE-2026-0390 | MEDIUM | 6.7 | 0.3% | Apr 14, 2026 | Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a sec... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now