2026 CVE Vulnerabilities
56,866 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20815 | HIGH | 7 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem... |
| CVE-2026-20814 | HIGH | 7 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an... |
| CVE-2026-20811 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to... |
| CVE-2026-20810 | HIGH | 7.8 | 0.5% | Jan 13, 2026 | Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate... |
| CVE-2026-20809 | HIGH | 7.8 | 0.4% | Jan 13, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate priv... |
| CVE-2026-20808 | HIGH | 7 | 0.3% | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Objec... |
| CVE-2026-20804 | HIGH | 7.7 | 0.5% | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. |
| CVE-2026-20803 | HIGH | 7.2 | 1.2% | Jan 13, 2026 | Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a ne... |
| CVE-2026-0386 | HIGH | 7.5 | 0.5% | Jan 13, 2026 | Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent ... |
| CVE-2026-0408 | HIGH | 8 | 0.2% | Jan 13, 2026 | A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the... |
| CVE-2026-0407 | HIGH | 8 | 0.2% | Jan 13, 2026 | An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with Wi... |
| CVE-2026-0406 | HIGH | 8 | 0.2% | Jan 13, 2026 | An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN t... |
| CVE-2026-0405 | HIGH | 7.8 | 0.3% | Jan 13, 2026 | An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access th... |
| CVE-2026-0404 | HIGH | 8 | 1.1% | Jan 13, 2026 | An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent at... |
| CVE-2026-0403 | HIGH | 8 | 0.3% | Jan 13, 2026 | An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN t... |
| CVE-2026-0891 | HIGH | 8.1 | 0.4% | Jan 13, 2026 | Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these b... |
| CVE-2026-0889 | HIGH | 7.5 | 0.5% | Jan 13, 2026 | Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147... |
| CVE-2026-0882 | HIGH | 8.8 | 0.4% | Jan 13, 2026 | Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7,... |
| CVE-2026-0880 | HIGH | 8.8 | 0.6% | Jan 13, 2026 | Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox E... |
| CVE-2026-0878 | HIGH | 8 | 0.4% | Jan 13, 2026 | Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed... |
| CVE-2026-0877 | HIGH | 8.1 | 0.4% | Jan 13, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firef... |
| CVE-2026-0859 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious... |
| CVE-2026-0511 | HIGH | 8.1 | 0.3% | Jan 13, 2026 | SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated u... |
| CVE-2026-0507 | HIGH | 8.4 | 0.9% | Jan 13, 2026 | Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticat... |
| CVE-2026-0506 | HIGH | 8.1 | 0.2% | Jan 13, 2026 | Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attack... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now