2026 CVE Vulnerabilities

53,618 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-20872MEDIUM6.5External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network...
CVE-2026-20862MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker ...
CVE-2026-20851MEDIUM6.2Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose informat...
CVE-2026-20847MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spo...
CVE-2026-20839MEDIUM5.5Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose informati...
CVE-2026-20838MEDIUM5.5Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose...
CVE-2026-20835MEDIUM5.5Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose informatio...
CVE-2026-20834MEDIUM4.6Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
CVE-2026-20833MEDIUM5.5Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose informati...
CVE-2026-20829MEDIUM5.5Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
CVE-2026-20828MEDIUM4.6Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information ...
CVE-2026-20827MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an...
CVE-2026-20825MEDIUM4.4Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-20824MEDIUM5.5Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature l...
CVE-2026-20823MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-20821MEDIUM6.2Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attac...
CVE-2026-20819MEDIUM5.5Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to di...
CVE-2026-20818MEDIUM6.2Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose informati...
CVE-2026-20812MEDIUM6.5Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perfo...
CVE-2026-20805MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to d...
CVE-2026-0890MEDIUM5.4Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ...
CVE-2026-0888MEDIUM5.3Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
CVE-2026-0887MEDIUM4.3Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Fir...
CVE-2026-0886MEDIUM5.3Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32...
CVE-2026-0885MEDIUM6.5Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderb...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now