2026 CVE Vulnerabilities

56,990 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50332HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50331HIGH7.8Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.
CVE-2026-50330CRITICAL9.8Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network...
CVE-2026-50329HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50328HIGH7.5Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
CVE-2026-50327HIGH7.8Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
CVE-2026-50326HIGH7.8Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
CVE-2026-50324MEDIUM5.9Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho...
CVE-2026-50322HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-50321HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows...
CVE-2026-50317HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems...
CVE-2026-50315HIGH7.8Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
CVE-2026-50314HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-50313HIGH7.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50312HIGH7.8Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-50310MEDIUM4.7Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information ...
CVE-2026-50309HIGH7.8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50307HIGH7.8Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-50306HIGH7.8Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-50305HIGH7.8Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50304HIGH7.5Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over...
CVE-2026-50302MEDIUM6.5Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security f...
CVE-2026-50301HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-4018MEDIUM6.4TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local acce...
CVE-2026-4017HIGH7.4Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now