2026 CVE Vulnerabilities

43,308 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61925HIGH7.8Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-61924MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61923HIGH7.8Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges lo...
CVE-2026-61921MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61920MEDIUM6.6Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut...
CVE-2026-61918MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61368MEDIUM5Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-61367HIGH7.8Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate...
CVE-2026-61366HIGH7Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
CVE-2026-61365HIGH7.8Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate...
CVE-2026-61364HIGH7.8Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate...
CVE-2026-61363HIGH7.5Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-61361HIGH7Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
CVE-2026-61360MEDIUM5.5Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-61359HIGH7.8Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-61358HIGH7.8Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) al...
CVE-2026-61357HIGH7.8Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61356HIGH7.8Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate...
CVE-2026-61355HIGH7.8Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61353HIGH7.8Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61352HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all...
CVE-2026-61350MEDIUM4.6Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-61349HIGH7.8Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61348HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-61347MEDIUM5.5Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now