2026 CVE Vulnerabilities

43,297 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63516MEDIUM6.5Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over ...
CVE-2026-63515HIGH7.8Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63514HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-63513HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63512MEDIUM6.5Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network...
CVE-2026-62917MEDIUM4.6Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ...
CVE-2026-62915MEDIUM6.5Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net...
CVE-2026-62914HIGH7.3Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows...
CVE-2026-62913HIGH8.8Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62912MEDIUM6.5Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw...
CVE-2026-62911HIGH8Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges...
CVE-2026-62910HIGH7.2Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attack...
CVE-2026-62909HIGH7.8Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62908HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all...
CVE-2026-62902MEDIUM6.5Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information...
CVE-2026-62901HIGH7.5Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62900MEDIUM5.9Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose...
CVE-2026-62899MEDIUM5.9Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker...
CVE-2026-62898HIGH7.5Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62897HIGH7Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62894HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-62893CRITICAL9.8Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-62892HIGH7Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges loca...
CVE-2026-62890HIGH7.8Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
CVE-2026-62889HIGH8.1Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a ne...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now