2026 CVE Vulnerabilities

56,405 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-21226HIGH7.5Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execut...
CVE-2026-21224HIGH7.8Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally...
CVE-2026-21221HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem...
CVE-2026-21219HIGH7Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2026-20965HIGH7.5Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privil...
CVE-2026-20957HIGH7.8Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally...
CVE-2026-20956HIGH7.8Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20955HIGH7.8Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20953HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20952HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20951HIGH7.8Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
CVE-2026-20950HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20949HIGH7.8Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-20948HIGH7.8Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20947HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allo...
CVE-2026-20946HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20944HIGH8.4Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20943HIGH7Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20941HIGH7.8Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized at...
CVE-2026-20940HIGH7.8Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges...
CVE-2026-20938HIGH7.8Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to el...
CVE-2026-20934HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows...
CVE-2026-20931HIGH8External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges o...
CVE-2026-20929HIGH7.5Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
CVE-2026-20926HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now