2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-69641 | CRITICAL | 9.1 | 0.8% | Sep 8, 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69595 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a netw... |
| CVE-2026-69590 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access... |
| CVE-2026-69586 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69579 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69525 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69496 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69493 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69491 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a netwo... |
| CVE-2026-69463 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69431 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69408 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code ove... |
| CVE-2026-69356 | CRITICAL | 9.3 | 0.7% | Sep 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows... |
| CVE-2026-69276 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to exe... |
| CVE-2026-68839 | CRITICAL | 9.8 | 1.0% | Sep 8, 2026 | Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over... |
| CVE-2026-67643 | CRITICAL | 9.8 | 0.8% | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-67636 | CRITICAL | 9 | 0.5% | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-67631 | CRITICAL | 9.8 | 0.6% | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-67378 | CRITICAL | 9 | 0.5% | Sep 8, 2026 | Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-65669 | CRITICAL | 9.6 | — | Sep 8, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows ... |
| CVE-2026-82533 | CRITICAL | 9.6 | 0.4% | Sep 8, 2026 | DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access... |
| CVE-2026-79570 | CRITICAL | 9.8 | 0.2% | Sep 8, 2026 | mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbCon... |
| CVE-2026-79569 | CRITICAL | 9.8 | 0.4% | Sep 8, 2026 | Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. Th... |
| CVE-2026-78997 | CRITICAL | 9.3 | 0.2% | Sep 8, 2026 | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulner... |
| CVE-2026-75156 | CRITICAL | 9.1 | 0.2% | Sep 8, 2026 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now