2026 CVE Vulnerabilities
56,236 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21253 | HIGH | 7 | 0.8% | Feb 10, 2026 | Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21251 | HIGH | 7.8 | 0.4% | Feb 10, 2026 | Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21250 | HIGH | 7.8 | 1.0% | Feb 10, 2026 | Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21248 | HIGH | 7.3 | 1.2% | Feb 10, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. |
| CVE-2026-21247 | HIGH | 7.3 | 0.5% | Feb 10, 2026 | Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. |
| CVE-2026-21246 | HIGH | 7.8 | 0.4% | Feb 10, 2026 | Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21245 | HIGH | 7.8 | 0.4% | Feb 10, 2026 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21244 | HIGH | 7.3 | 1.2% | Feb 10, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. |
| CVE-2026-21243 | HIGH | 7.5 | 1.3% | Feb 10, 2026 | Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny... |
| CVE-2026-21242 | HIGH | 7 | 0.3% | Feb 10, 2026 | Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21241 | HIGH | 7 | 2.5% | Feb 10, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca... |
| CVE-2026-21240 | HIGH | 7 | 0.3% | Feb 10, 2026 | Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privilege... |
| CVE-2026-21239 | HIGH | 7.8 | 0.4% | Feb 10, 2026 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21238 | HIGH | 7.8 | 3.2% | Feb 10, 2026 | Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privil... |
| CVE-2026-21237 | HIGH | 7 | 0.3% | Feb 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Lin... |
| CVE-2026-21236 | HIGH | 7.8 | 0.4% | Feb 10, 2026 | Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pri... |
| CVE-2026-21235 | HIGH | 7.3 | 0.7% | Feb 10, 2026 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21234 | HIGH | 7 | 0.3% | Feb 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices... |
| CVE-2026-21232 | HIGH | 7.8 | 0.4% | Feb 10, 2026 | Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21231 | HIGH | 7.8 | 2.4% | Feb 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an ... |
| CVE-2026-21229 | HIGH | 8.8 | 0.9% | Feb 10, 2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. |
| CVE-2026-21228 | HIGH | 8.1 | 0.7% | Feb 10, 2026 | Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. |
| CVE-2026-21218 | HIGH | 7.5 | 1.0% | Feb 10, 2026 | Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-20846 | HIGH | 7.5 | 1.3% | Feb 10, 2026 | Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. |
| CVE-2026-20841 | HIGH | 7.8 | 11.7% | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an una... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now