2026 CVE Vulnerabilities

48,567 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34701HIGH7.8InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-34700HIGH7.8InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-34699HIGH7.8InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-34698HIGH7.8InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-34697HIGH7.8InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that coul...
CVE-2026-34696HIGH7.8InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Use After Free vulnerability that could result in a...
CVE-2026-34695HIGH7.8InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that coul...
CVE-2026-34693HIGH8Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripti...
CVE-2026-9213HIGH8.1A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with tr...
CVE-2026-9212HIGH8Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network...
CVE-2026-9211HIGH8.8An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operati...
CVE-2026-9076HIGH7.5Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an ...
CVE-2026-7383HIGH8.1Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() ...
CVE-2026-50508HIGH7.5Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp...
CVE-2026-49959HIGH8.8Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers ...
CVE-2026-49957HIGH7.7Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attack...
CVE-2026-49956HIGH7.1Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users t...
CVE-2026-49847HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49842HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49475HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49161HIGH7.8Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
CVE-2026-49160HIGH7.5Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
CVE-2026-48583HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-48578HIGH7.9Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
CVE-2026-48576HIGH7.9No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now