2026 CVE Vulnerabilities

52,737 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32178HIGH7.5Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32176HIGH7.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2026-32171HIGH8.8Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a netw...
CVE-2026-32168HIGH7.8Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-32167HIGH7.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2026-32165HIGH7.8Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
CVE-2026-32164HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Co...
CVE-2026-32163HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Co...
CVE-2026-32162HIGH8.4Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate priv...
CVE-2026-32160HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-32159HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-32158HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-32157HIGH8.8Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-32156HIGH7.4Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code loc...
CVE-2026-32155HIGH7.8Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-32154HIGH7.8Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-32153HIGH7.8Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
CVE-2026-32152HIGH7.8Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-32150HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic...
CVE-2026-32149HIGH7.3Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
CVE-2026-32093HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic...
CVE-2026-32091HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File ...
CVE-2026-32090HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech Brokered A...
CVE-2026-32089HIGH7.8Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
CVE-2026-32087HIGH7Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now