2026 CVE Vulnerabilities
69,799 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26117 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized att... |
| CVE-2026-26116 | HIGH | 8.8 | 1.2% | Mar 10, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ... |
| CVE-2026-26115 | HIGH | 8.8 | 1.1% | Mar 10, 2026 | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a ... |
| CVE-2026-26114 | HIGH | 8.8 | 2.4% | Mar 10, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2026-26113 | HIGH | 7.8 | 0.5% | Mar 10, 2026 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-26112 | HIGH | 7.8 | 0.5% | Mar 10, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-26111 | HIGH | 8 | 0.8% | Mar 10, 2026 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec... |
| CVE-2026-26110 | HIGH | 7.8 | 0.5% | Mar 10, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe... |
| CVE-2026-26109 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-26108 | HIGH | 7.8 | 0.5% | Mar 10, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-26107 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-26106 | HIGH | 8.8 | 1.4% | Mar 10, 2026 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-26105 | CRITICAL | 9.3 | 1.3% | Mar 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-25972 | MEDIUM | 6.1 | 0.3% | Mar 10, 2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS... |
| CVE-2026-25836 | HIGH | 7.2 | 1.8% | Mar 10, 2026 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ... |
| CVE-2026-25689 | MEDIUM | 6.5 | 0.5% | Mar 10, 2026 | An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec... |
| CVE-2026-25605 | HIGH | 7.1 | 0.1% | Mar 10, 2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file d... |
| CVE-2026-25573 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell co... |
| CVE-2026-25572 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component doe... |
| CVE-2026-25571 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component doe... |
| CVE-2026-25570 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform che... |
| CVE-2026-25569 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exi... |
| CVE-2026-25190 | HIGH | 7.8 | 0.5% | Mar 10, 2026 | Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. |
| CVE-2026-25189 | HIGH | 7.8 | 0.3% | Mar 10, 2026 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2026-25188 | HIGH | 8.8 | 0.6% | Mar 10, 2026 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an ad... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now