2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48356 | CRITICAL | 9.3 | 28.2% | Jul 14, 2026 | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi... |
| CVE-2026-48259 | CRITICAL | 9.6 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrar... |
| CVE-2026-47428 | CRITICAL | 9.6 | 0.4% | Jul 14, 2026 | Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__v... |
| CVE-2026-15409 | CRITICAL | 10 | 1.4% | Jul 14, 2026 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A ... |
| CVE-2026-13001 | CRITICAL | 9.8 | — | Jul 14, 2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali... |
| CVE-2026-47767 | CRITICAL | 9.8 | 0.4% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.... |
| CVE-2026-47304 | CRITICAL | 9.8 | 0.2% | Jul 14, 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov... |
| CVE-2026-45069 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1... |
| CVE-2026-45063 | CRITICAL | 9.1 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-58617 | CRITICAL | 9.8 | 0.7% | Jul 14, 2026 | Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a ne... |
| CVE-2026-58594 | CRITICAL | 9.8 | 0.8% | Jul 14, 2026 | Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. |
| CVE-2026-57092 | CRITICAL | 9.9 | 1.0% | Jul 14, 2026 | Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-57090 | CRITICAL | 9.8 | 0.8% | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a ... |
| CVE-2026-57089 | CRITICAL | 9.8 | 0.6% | Jul 14, 2026 | Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute co... |
| CVE-2026-56190 | CRITICAL | 9.8 | 0.9% | Jul 14, 2026 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. |
| CVE-2026-56159 | CRITICAL | 9.8 | 0.8% | Jul 14, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-55944 | CRITICAL | 9.8 | 1.3% | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a netwo... |
| CVE-2026-55040 | CRITICAL | 9.1 | 0.7% | Jul 14, 2026 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a n... |
| CVE-2026-55010 | CRITICAL | 9.8 | 0.8% | Jul 14, 2026 | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a ... |
| CVE-2026-50518 | CRITICAL | 9.8 | 7.4% | Jul 14, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-50487 | CRITICAL | 9.8 | 0.7% | Jul 14, 2026 | Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-50447 | CRITICAL | 9.8 | 0.9% | Jul 14, 2026 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
| CVE-2026-50439 | CRITICAL | 9.8 | 0.5% | Jul 14, 2026 | Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network... |
| CVE-2026-50380 | CRITICAL | 9.6 | 0.6% | Jul 14, 2026 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
| CVE-2026-50330 | CRITICAL | 9.8 | 1.1% | Jul 14, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now