2026 CVE Vulnerabilities
56,852 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20857 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privile... |
| CVE-2026-20856 | HIGH | 8.1 | 1.1% | Jan 13, 2026 | Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a networ... |
| CVE-2026-20854 | HIGH | 7.5 | 1.0% | Jan 13, 2026 | Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute co... |
| CVE-2026-20853 | HIGH | 7.4 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService all... |
| CVE-2026-20852 | HIGH | 7.7 | 0.5% | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. |
| CVE-2026-20849 | HIGH | 7.5 | 1.0% | Jan 13, 2026 | Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privile... |
| CVE-2026-20848 | HIGH | 7.5 | 0.7% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows... |
| CVE-2026-20844 | HIGH | 7.4 | 0.3% | Jan 13, 2026 | Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-20843 | HIGH | 7.8 | 3.3% | Jan 13, 2026 | Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pri... |
| CVE-2026-20842 | HIGH | 7 | 0.4% | Jan 13, 2026 | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20840 | HIGH | 7.8 | 4.4% | Jan 13, 2026 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
| CVE-2026-20837 | HIGH | 7.8 | 0.7% | Jan 13, 2026 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
| CVE-2026-20836 | HIGH | 7 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an... |
| CVE-2026-20832 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability |
| CVE-2026-20831 | HIGH | 7 | 0.3% | Jan 13, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized ... |
| CVE-2026-20830 | HIGH | 7 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem... |
| CVE-2026-20826 | HIGH | 7 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Inter... |
| CVE-2026-20822 | HIGH | 7.8 | 0.4% | Jan 13, 2026 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20820 | HIGH | 7.8 | 2.5% | Jan 13, 2026 | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ... |
| CVE-2026-20817 | HIGH | 7.8 | 5.3% | Jan 13, 2026 | Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to ... |
| CVE-2026-20816 | HIGH | 7 | 2.4% | Jan 13, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileg... |
| CVE-2026-20815 | HIGH | 7 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem... |
| CVE-2026-20814 | HIGH | 7 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an... |
| CVE-2026-20811 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to... |
| CVE-2026-20810 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now