2026 CVE Vulnerabilities

56,993 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49798CRITICAL9.3Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2026-49797HIGH7.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-49796HIGH7.8Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
CVE-2026-49795HIGH8.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49794MEDIUM4.6Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat...
CVE-2026-49793HIGH7.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally...
CVE-2026-49792HIGH7.8Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-49791HIGH7.8Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow...
CVE-2026-49790HIGH7.8Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-49789HIGH7.8Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-49788HIGH7.5Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a ne...
CVE-2026-49787HIGH7.5Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service...
CVE-2026-49784HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Sto...
CVE-2026-49783HIGH7.8Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a secu...
CVE-2026-49184HIGH7.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-49183HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server ...
CVE-2026-49181CRITICAL9.8Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over...
CVE-2026-49180MEDIUM5.5Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize...
CVE-2026-49178HIGH8.8Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a netw...
CVE-2026-49176HIGH7.8Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
CVE-2026-49175HIGH7.8Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-49174MEDIUM6.1Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering...
CVE-2026-49173HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49172CRITICAL9.8Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
CVE-2026-49171HIGH7.8Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now