2026 CVE Vulnerabilities
56,405 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21226 | HIGH | 7.5 | 0.8% | Jan 13, 2026 | Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execut... |
| CVE-2026-21224 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally... |
| CVE-2026-21221 | HIGH | 7 | 0.2% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem... |
| CVE-2026-21219 | HIGH | 7 | 0.3% | Jan 13, 2026 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
| CVE-2026-20965 | HIGH | 7.5 | 0.2% | Jan 13, 2026 | Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privil... |
| CVE-2026-20957 | HIGH | 7.8 | 0.4% | Jan 13, 2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally... |
| CVE-2026-20956 | HIGH | 7.8 | 0.4% | Jan 13, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-20955 | HIGH | 7.8 | 0.6% | Jan 13, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-20953 | HIGH | 8.4 | 0.6% | Jan 13, 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-20952 | HIGH | 8.4 | 0.5% | Jan 13, 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-20951 | HIGH | 7.8 | 0.8% | Jan 13, 2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. |
| CVE-2026-20950 | HIGH | 7.8 | 0.4% | Jan 13, 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-20949 | HIGH | 7.8 | 0.4% | Jan 13, 2026 | Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2026-20948 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-20947 | HIGH | 8.8 | 17.9% | Jan 13, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allo... |
| CVE-2026-20946 | HIGH | 7.8 | 0.7% | Jan 13, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-20944 | HIGH | 8.4 | 0.5% | Jan 13, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-20943 | HIGH | 7 | 0.6% | Jan 13, 2026 | Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-20941 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized at... |
| CVE-2026-20940 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges... |
| CVE-2026-20938 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to el... |
| CVE-2026-20934 | HIGH | 7.5 | 0.8% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows... |
| CVE-2026-20931 | HIGH | 8 | 0.8% | Jan 13, 2026 | External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges o... |
| CVE-2026-20929 | HIGH | 7.5 | 1.1% | Jan 13, 2026 | Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-20926 | HIGH | 7.5 | 0.8% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now