2026 CVE Vulnerabilities

55,483 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25173HIGH8Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec...
CVE-2026-25172HIGH8Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec...
CVE-2026-25171HIGH7Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
CVE-2026-25170HIGH7Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2026-25167HIGH7.4Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
CVE-2026-25166HIGH7.8Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.
CVE-2026-25165HIGH7.8Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.
CVE-2026-24296HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Associatio...
CVE-2026-24295HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Associatio...
CVE-2026-24294HIGH7.8Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
CVE-2026-24293HIGH7.8Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi...
CVE-2026-24292HIGH7.8Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locall...
CVE-2026-24291HIGH7.8Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an a...
CVE-2026-24290HIGH7.8Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-24289HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-24287HIGH7.8External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-24285HIGH7Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-24283HIGH8.8Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.
CVE-2026-24018HIGH7.8A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinu...
CVE-2026-24017HIGH8.1An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8....
CVE-2026-23674HIGH7.5Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security fea...
CVE-2026-23673HIGH7.8Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-23672HIGH7.8Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-23671HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM P...
CVE-2026-23669HIGH8.8Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now