2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49921 | CRITICAL | 9.8 | 0.4% | Sep 8, 2026 | In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote ... |
| CVE-2026-28606 | CRITICAL | 9.8 | 0.3% | Sep 8, 2026 | In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the co... |
| CVE-2026-81376 | CRITICAL | 9.6 | 0.7% | Sep 8, 2026 | Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security fe... |
| CVE-2026-81352 | CRITICAL | 9.8 | 0.5% | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a ne... |
| CVE-2026-78509 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
| CVE-2026-78445 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a netw... |
| CVE-2026-77493 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
| CVE-2026-73025 | CRITICAL | 9.8 | 0.9% | Sep 8, 2026 | Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-73010 | CRITICAL | 9.8 | 0.9% | Sep 8, 2026 | Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. |
| CVE-2026-73009 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a... |
| CVE-2026-72983 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a netwo... |
| CVE-2026-72982 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. |
| CVE-2026-72979 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-72950 | CRITICAL | 9.8 | 0.9% | Sep 8, 2026 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access... |
| CVE-2026-70296 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69910 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69854 | CRITICAL | 9 | 0.6% | Sep 8, 2026 | Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69845 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69829 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69824 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a ... |
| CVE-2026-69819 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69769 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network... |
| CVE-2026-69768 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69730 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69715 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now