57,566 vulnerabilities published in 2026
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privilege
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges l
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code loc
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privile
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges local
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privilege
Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows a
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to ele
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started