2026 CVE Vulnerabilities

51,024 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40413HIGH7.4Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40410HIGH7Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVE-2026-40408HIGH7.8Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-40407HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2026-40406HIGH7.5Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.
CVE-2026-40405HIGH7.5Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
CVE-2026-40403HIGH8.8Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
CVE-2026-40401HIGH7.1Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40399HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an ...
CVE-2026-40398HIGH7.8Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
CVE-2026-40397HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2026-40382HIGH7.8Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-40381HIGH7.8Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-40379HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform ...
CVE-2026-40377HIGH7.8Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally...
CVE-2026-40370HIGH8.8External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-40369HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-40368HIGH8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-40367HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40366HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40365HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-40364HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40363HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40362HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40361HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now