2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65813MEDIUM6.5Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over...
CVE-2026-65811HIGH8.8Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-65810HIGH7.8Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-65807HIGH8.8Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ...
CVE-2026-65806MEDIUM6.5Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
CVE-2026-65799MEDIUM6.7Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65798MEDIUM6.7Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65797MEDIUM6.7Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65796MEDIUM5.9Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a networ...
CVE-2026-65795MEDIUM6.7No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65794MEDIUM6.5Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-65791CRITICAL9.8Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ...
CVE-2026-65790HIGH7.8Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2026-65789HIGH8.1Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-65788HIGH7Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-65787HIGH7.8Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-65786HIGH7.8Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-65785MEDIUM6.5Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacen...
CVE-2026-65784MEDIUM5.5Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-65783HIGH7Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65782HIGH7Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65781HIGH7Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65780HIGH7Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65779HIGH7Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65778HIGH7Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now