2026 CVE Vulnerabilities

56,989 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50392HIGH7Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-50391HIGH7.8Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.
CVE-2026-50390HIGH7.8Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate...
CVE-2026-50389MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-50388HIGH7.8Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50387HIGH7.8Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-50386HIGH7.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50385HIGH8.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-50383MEDIUM5.5Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVE-2026-50382HIGH8.8Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
CVE-2026-50380CRITICAL9.6Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2026-50379HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50378HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows ...
CVE-2026-50377HIGH7.8Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50376MEDIUM6.5Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50375HIGH7.8Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-50374MEDIUM6.8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a phys...
CVE-2026-50373HIGH7.8Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locall...
CVE-2026-50372HIGH7Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
CVE-2026-50371HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an a...
CVE-2026-50370HIGH8.8Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent netwo...
CVE-2026-50369HIGH8.8Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
CVE-2026-50368HIGH7.5Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over...
CVE-2026-50367HIGH7.8Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to e...
CVE-2026-50366MEDIUM6.5Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now