2026 CVE Vulnerabilities

51,016 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-42896HIGH7.8Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-42893HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-42831HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-42825HIGH7Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-42348HIGH7.5OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses ...
CVE-2026-42141HIGH7.7Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-41895HIGH7.5changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches ...
CVE-2026-41613HIGH8.8Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41109HIGH8.8Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and...
CVE-2026-41107HIGH7.4External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose inf...
CVE-2026-41095HIGH7.8Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
CVE-2026-41094HIGH8.8Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker t...
CVE-2026-41088HIGH7.8Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an...
CVE-2026-41086HIGH8.8Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-40420HIGH8.8Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40419HIGH7.8Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40418HIGH7.8Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40417HIGH7.8Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
CVE-2026-40415HIGH8.1Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
CVE-2026-40414HIGH7.4Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40413HIGH7.4Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40410HIGH7Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVE-2026-40408HIGH7.8Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-40407HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2026-40406HIGH7.5Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now