2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-48356CRITICAL9.3Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi...
CVE-2026-48259CRITICAL9.6Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrar...
CVE-2026-47428CRITICAL9.6Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__v...
CVE-2026-15409CRITICAL10A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A ...
CVE-2026-13001CRITICAL9.8The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...
CVE-2026-47767CRITICAL9.8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4....
CVE-2026-47304CRITICAL9.8Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov...
CVE-2026-45069CRITICAL9.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1...
CVE-2026-45063CRITICAL9.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-58617CRITICAL9.8Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a ne...
CVE-2026-58594CRITICAL9.8Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
CVE-2026-57092CRITICAL9.9Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
CVE-2026-57090CRITICAL9.8Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a ...
CVE-2026-57089CRITICAL9.8Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute co...
CVE-2026-56190CRITICAL9.8Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
CVE-2026-56159CRITICAL9.8Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-55944CRITICAL9.8Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a netwo...
CVE-2026-55040CRITICAL9.1Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a n...
CVE-2026-55010CRITICAL9.8Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a ...
CVE-2026-50518CRITICAL9.8Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50487CRITICAL9.8Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50447CRITICAL9.8Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-50439CRITICAL9.8Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network...
CVE-2026-50380CRITICAL9.6Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2026-50330CRITICAL9.8Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now