2026 CVE Vulnerabilities

53,639 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25165HIGH7.8Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.
CVE-2026-24296HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Associatio...
CVE-2026-24295HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Associatio...
CVE-2026-24294HIGH7.8Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
CVE-2026-24293HIGH7.8Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi...
CVE-2026-24292HIGH7.8Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locall...
CVE-2026-24291HIGH7.8Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an a...
CVE-2026-24290HIGH7.8Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-24289HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-24287HIGH7.8External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-24285HIGH7Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-24283HIGH8.8Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.
CVE-2026-24018HIGH7.8A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinu...
CVE-2026-24017HIGH8.1An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8....
CVE-2026-23674HIGH7.5Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security fea...
CVE-2026-23673HIGH7.8Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-23672HIGH7.8Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-23671HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM P...
CVE-2026-23669HIGH8.8Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
CVE-2026-23668HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2026-23667HIGH7Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
CVE-2026-23665HIGH7.8Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.
CVE-2026-23664HIGH7.5Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacke...
CVE-2026-23662HIGH7.5Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose informati...
CVE-2026-23661HIGH7.5Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose inform...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now