2026 CVE Vulnerabilities
56,405 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20924 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20923 | HIGH | 7.8 | 0.4% | Jan 13, 2026 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20922 | HIGH | 7.8 | 1.0% | Jan 13, 2026 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
| CVE-2026-20921 | HIGH | 7.5 | 1.2% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows... |
| CVE-2026-20920 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20919 | HIGH | 7.5 | 0.8% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows... |
| CVE-2026-20918 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic... |
| CVE-2026-20877 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20875 | HIGH | 7.5 | 1.5% | Jan 13, 2026 | Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker t... |
| CVE-2026-20874 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic... |
| CVE-2026-20873 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic... |
| CVE-2026-20871 | HIGH | 7.8 | 4.0% | Jan 13, 2026 | Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20870 | HIGH | 7.8 | 0.4% | Jan 13, 2026 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20869 | HIGH | 7 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Man... |
| CVE-2026-20868 | HIGH | 8.8 | 1.3% | Jan 13, 2026 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2026-20867 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic... |
| CVE-2026-20866 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic... |
| CVE-2026-20865 | HIGH | 7.8 | 0.4% | Jan 13, 2026 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20864 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privi... |
| CVE-2026-20863 | HIGH | 7 | 0.4% | Jan 13, 2026 | Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20861 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic... |
| CVE-2026-20860 | HIGH | 7.8 | 8.0% | Jan 13, 2026 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an... |
| CVE-2026-20859 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20858 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20857 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privile... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now