2026 CVE Vulnerabilities

48,586 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-45598HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio...
CVE-2026-45597HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (ui...
CVE-2026-45596HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-45593HIGH7.8Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.
CVE-2026-45592HIGH7.8Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges loc...
CVE-2026-45591HIGH7.5Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-45588HIGH7.9Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-45586HIGH7.8Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an ...
CVE-2026-45583HIGH8.1Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker t...
CVE-2026-45504HIGH8.8Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over...
CVE-2026-45490HIGH7.8Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-45487HIGH7Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attack...
CVE-2026-45486HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45484HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove...
CVE-2026-45482HIGH8.4Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code ...
CVE-2026-45476HIGH8.2Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-45475HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45474HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45472HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45471HIGH7.8Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45469HIGH7.8Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally...
CVE-2026-45463HIGH8.4Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45461HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45458HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45457HIGH7.8Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now