2026 CVE Vulnerabilities
43,308 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62766 | HIGH | 7 | — | Aug 11, 2026 | Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62761 | HIGH | 7.8 | — | Aug 11, 2026 | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to e... |
| CVE-2026-62758 | HIGH | 7.8 | — | Aug 11, 2026 | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileg... |
| CVE-2026-62757 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a securit... |
| CVE-2026-62755 | HIGH | 7.8 | — | Aug 11, 2026 | Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62754 | HIGH | 7.8 | — | Aug 11, 2026 | Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62753 | HIGH | 7 | — | Aug 11, 2026 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62752 | HIGH | 7.8 | — | Aug 11, 2026 | Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62751 | HIGH | 7.8 | — | Aug 11, 2026 | Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges loca... |
| CVE-2026-62750 | MEDIUM | 6.5 | — | Aug 11, 2026 | Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an ad... |
| CVE-2026-62749 | HIGH | 7 | — | Aug 11, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62748 | HIGH | 7 | — | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service... |
| CVE-2026-62747 | HIGH | 7.8 | — | Aug 11, 2026 | Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges loc... |
| CVE-2026-62746 | MEDIUM | 5.5 | — | Aug 11, 2026 | Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. |
| CVE-2026-62745 | MEDIUM | 6.5 | — | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov... |
| CVE-2026-62743 | MEDIUM | 5.5 | — | Aug 11, 2026 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
| CVE-2026-62742 | MEDIUM | 6.5 | 0.5% | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov... |
| CVE-2026-62741 | HIGH | 7.8 | — | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62740 | MEDIUM | 5.5 | — | Aug 11, 2026 | Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally... |
| CVE-2026-62739 | HIGH | 7.8 | — | Aug 11, 2026 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62738 | MEDIUM | 5.5 | — | Aug 11, 2026 | Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. |
| CVE-2026-62737 | HIGH | 7.8 | — | Aug 11, 2026 | Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62736 | HIGH | 7.8 | — | Aug 11, 2026 | Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62735 | HIGH | 7.8 | — | Aug 11, 2026 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62734 | HIGH | 7 | — | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now