2026 CVE Vulnerabilities

56,980 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45069CRITICAL9.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1...
CVE-2026-45064MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until...
CVE-2026-45063CRITICAL9.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-15720HIGH8.6In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler...
CVE-2026-15712MEDIUM5.9A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tra...
CVE-2026-15642LOW3.3Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Serve...
CVE-2026-15641HIGH7.1Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authen...
CVE-2026-15637HIGH7.5Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.2...
CVE-2026-15058LOW3.1Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an aut...
CVE-2026-62659MEDIUM4.3A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connect...
CVE-2026-62658MEDIUM4.7A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged i...
CVE-2026-62657MEDIUM4.9A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and ce...
CVE-2026-62656MEDIUM5.4A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requ...
CVE-2026-62655MEDIUM5.7A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to st...
CVE-2026-58638MEDIUM5.5Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
CVE-2026-58637HIGH7Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58634HIGH7.8Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58633HIGH7.8Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58632HIGH7.8Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-58629HIGH7Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-58628HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networki...
CVE-2026-58627HIGH7.5Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-58626HIGH8.8Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
CVE-2026-58619HIGH7Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58617CRITICAL9.8Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a ne...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now