2026 CVE Vulnerabilities

56,852 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-20857HIGH7.8Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privile...
CVE-2026-20856HIGH8.1Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a networ...
CVE-2026-20854HIGH7.5Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute co...
CVE-2026-20853HIGH7.4Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService all...
CVE-2026-20852HIGH7.7Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
CVE-2026-20849HIGH7.5Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privile...
CVE-2026-20848HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows...
CVE-2026-20844HIGH7.4Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
CVE-2026-20843HIGH7.8Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pri...
CVE-2026-20842HIGH7Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2026-20840HIGH7.8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-20837HIGH7.8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-20836HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an...
CVE-2026-20832HIGH7.8Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
CVE-2026-20831HIGH7Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized ...
CVE-2026-20830HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem...
CVE-2026-20826HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Inter...
CVE-2026-20822HIGH7.8Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2026-20820HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2026-20817HIGH7.8Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to ...
CVE-2026-20816HIGH7Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileg...
CVE-2026-20815HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem...
CVE-2026-20814HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an...
CVE-2026-20811HIGH7.8Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to...
CVE-2026-20810HIGH7.8Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now