2026 CVE Vulnerabilities

56,985 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54128HIGH8.4Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
CVE-2026-54126MEDIUM6.5Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-54125HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-54124HIGH7.8Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
CVE-2026-54121HIGH8.8Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privile...
CVE-2026-54116MEDIUM6.5Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose in...
CVE-2026-54115HIGH7.8Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
CVE-2026-50692HIGH8.8Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-50690MEDIUM5.5Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVE-2026-50689HIGH7.8Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
CVE-2026-50688HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50687HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50686HIGH8.1Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute ...
CVE-2026-50685HIGH7.5Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVE-2026-50684MEDIUM4.8Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Serv...
CVE-2026-50683HIGH8Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent n...
CVE-2026-50682HIGH7.1Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
CVE-2026-50681MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack...
CVE-2026-50680HIGH7.8Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2026-50679HIGH7.8Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges loc...
CVE-2026-50677HIGH7.8Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50676HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50674HIGH7.8Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50673HIGH7.8Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50672HIGH7Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now