2026 CVE Vulnerabilities

56,989 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50418MEDIUM6.1Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-50417HIGH7.8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50416LOW3.3Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose i...
CVE-2026-50415HIGH7.5Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose ...
CVE-2026-50414HIGH8.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50413HIGH7.8Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50412HIGH7.8Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50411HIGH7.5Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv...
CVE-2026-50410HIGH7Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50409MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to di...
CVE-2026-50408MEDIUM5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-50407HIGH7.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges l...
CVE-2026-50406HIGH7.8Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
CVE-2026-50405HIGH7.8Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate ...
CVE-2026-50404HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50403HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-50402HIGH7.8Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50401MEDIUM5.5Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information local...
CVE-2026-50400HIGH7.8Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-50399HIGH7.8Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50398HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50397HIGH7Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50396HIGH7.8Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-50394MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in...
CVE-2026-50393HIGH7.8Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now