2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-69641CRITICAL9.1Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69595CRITICAL9.8Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a netw...
CVE-2026-69590CRITICAL9.8Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access...
CVE-2026-69586CRITICAL9.8Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
CVE-2026-69579CRITICAL9.8Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-69525CRITICAL9.8Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
CVE-2026-69496CRITICAL9.8Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
CVE-2026-69493CRITICAL9.8Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
CVE-2026-69491CRITICAL9.8Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a netwo...
CVE-2026-69463CRITICAL9.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
CVE-2026-69431CRITICAL9.8Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
CVE-2026-69408CRITICAL9.8Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code ove...
CVE-2026-69356CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows...
CVE-2026-69276CRITICAL9.8Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to exe...
CVE-2026-68839CRITICAL9.8Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over...
CVE-2026-67643CRITICAL9.8Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67636CRITICAL9Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67631CRITICAL9.8Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67378CRITICAL9Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-65669CRITICAL9.6Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows ...
CVE-2026-82533CRITICAL9.6DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access...
CVE-2026-79570CRITICAL9.8mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbCon...
CVE-2026-79569CRITICAL9.8Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. Th...
CVE-2026-78997CRITICAL9.3UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulner...
CVE-2026-75156CRITICAL9.1Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now