2026 CVE Vulnerabilities

51,043 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40368HIGH8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-40367HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40366HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40365HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-40364HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40363HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40362HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40361HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40360HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-40359HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40358HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40357HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-35439HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-35438HIGH8.3Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-35436HIGH8.8Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-35433HIGH7.3Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-35424HIGH7.5Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorize...
CVE-2026-35421HIGH7.8Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
CVE-2026-35420HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-35418HIGH7Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-35417HIGH7.8Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2026-35416HIGH7Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an...
CVE-2026-35415HIGH7.8Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges ...
CVE-2026-34687HIGH7.8Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resu...
CVE-2026-34676HIGH7.8Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now