Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Windows · Build corrective · Tous les builds Windows

10.0.28000.2525

Advisory MSRC

La build Windows 10.0.28000.2525, publiée le 2026-07-16, corrige 383 CVE, dont 1 activement exploitée (CISA KEV), déployée sur 1 SKU.

Publiée le
2026-07-16
SKU couvertes
1
CVE corrigées
383

9 critique · 277 élevé

KEV CISA
1

SKU Windows couvertes par cette build

Les SKU ci-dessous partagent ce numéro de build MSRC. Pousser la KB correspondante les sécurise toutes simultanément.

CVE corrigées par cette build

CVE
CVE-2026-32202
MEDIUM 4.3 KEV

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-57092
CRITICAL 9.9

Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.

CVE-2026-56190
CRITICAL 9.8

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

CVE-2026-56188
CRITICAL 9.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to…

CVE-2026-50447
CRITICAL 9.8

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

CVE-2026-54990
CRITICAL 9.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-49172
CRITICAL 9.8

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

CVE-2026-42990
CRITICAL 9.8

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

CVE-2026-50380
CRITICAL 9.6

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVE-2026-49798
CRITICAL 9.3

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

CVE-2026-58626
HIGH 8.8

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-58594
HIGH 8.8

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

CVE-2026-58534
HIGH 8.8

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

CVE-2026-57094
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57090
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57087
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-56647
HIGH 8.8

Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.

CVE-2026-56194
HIGH 8.8

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-50692
HIGH 8.8

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-50687
HIGH 8.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50670
HIGH 8.8

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50666
HIGH 8.8

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.

CVE-2026-50489
HIGH 8.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-50474
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-50477
HIGH 8.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50413
HIGH 8.8

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50398
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50385
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50382
HIGH 8.8

Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

CVE-2026-50369
HIGH 8.8

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

CVE-2026-50360
HIGH 8.8

Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-58608
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker t…

CVE-2026-54999
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o…

CVE-2026-54982
HIGH 8.8

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-54107
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg…

CVE-2026-50342
HIGH 8.8

Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-49795
HIGH 8.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49178
HIGH 8.8

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

CVE-2026-50340
HIGH 8.5

Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.

CVE-2026-54128
HIGH 8.4

Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.

CVE-2026-54992
HIGH 8.4

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

CVE-2026-54122
HIGH 8.4

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

CVE-2026-49184
HIGH 8.4

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-56181
HIGH 8.3

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2026-50680
HIGH 8.2

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-50429
HIGH 8.2

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

CVE-2026-56186
HIGH 8.1

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

CVE-2026-50686
HIGH 8.1

Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.

CVE-2026-50487
HIGH 8.1

Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50460
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi…

CVE-2026-50439
HIGH 8.1

Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.

CVE-2026-54995
HIGH 8.1

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

CVE-2026-50694
HIGH 8.1

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-49164
HIGH 8.1

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

CVE-2026-42900
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate pri…

CVE-2026-50502
HIGH 8.0

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

CVE-2026-50365
HIGH 8.0

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2026-42975
HIGH 8.0

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-40400
HIGH 8.0

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

CVE-2026-58632
HIGH 7.8

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-58633
HIGH 7.8

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58634
HIGH 7.8

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58613
HIGH 7.8

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58628
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to ele…

CVE-2026-58542
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-58538
HIGH 7.8

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58540
HIGH 7.8

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-58541
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2026-58532
HIGH 7.8

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-58537
HIGH 7.8

Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-58536
HIGH 7.8

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58527
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-58530
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVE-2026-57096
HIGH 7.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-57091
HIGH 7.8

Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-56650
HIGH 7.8

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

CVE-2026-56643
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-56644
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-56189
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVE-2026-56182
HIGH 7.8

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-56176
HIGH 7.8

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVE-2026-56175
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-54125
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-54124
HIGH 7.8

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

CVE-2026-54115
HIGH 7.8

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

CVE-2026-50689
HIGH 7.8

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

CVE-2026-50688
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50677
HIGH 7.8

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50679
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-50673
HIGH 7.8

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50676
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50667
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges…

CVE-2026-50655
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-50509
HIGH 7.8

Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50501
HIGH 7.8

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVE-2026-50499
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-50498
HIGH 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-50493
HIGH 7.8

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50494
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50484
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50486
HIGH 7.8

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50476
HIGH 7.8

Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.

CVE-2026-50478
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50471
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50469
HIGH 7.8

Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50466
HIGH 7.8

Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50462
HIGH 7.8

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-50461
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50454
HIGH 7.8

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

CVE-2026-50457
HIGH 7.8

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50458
HIGH 7.8

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50448
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50450
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized …

CVE-2026-50440
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate p…

CVE-2026-50441
HIGH 7.8

Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50433
HIGH 7.8

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50436
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50435
HIGH 7.8

Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

CVE-2026-50427
HIGH 7.8

Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-50425
HIGH 7.8

Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.

CVE-2026-50423
HIGH 7.8

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50422
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50421
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate priv…

CVE-2026-50412
HIGH 7.8

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50417
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50407
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50405
HIGH 7.8

Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.

CVE-2026-50400
HIGH 7.8

Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-50402
HIGH 7.8

Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50399
HIGH 7.8

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50391
HIGH 7.8

Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.

CVE-2026-50386
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50388
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50387
HIGH 7.8

Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.

CVE-2026-50378
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privi…

CVE-2026-50373
HIGH 7.8

Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-50367
HIGH 7.8

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50363
HIGH 7.8

Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-50361
HIGH 7.8

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50362
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVE-2026-50357
HIGH 7.8

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-50353
HIGH 7.8

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2026-50347
HIGH 7.8

Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.

CVE-2026-50346
HIGH 7.8

Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50344
HIGH 7.8

Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.

CVE-2026-50337
HIGH 7.8

Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

CVE-2026-50343
HIGH 7.8

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50336
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50332
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50331
HIGH 7.8

Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.

CVE-2026-50335
HIGH 7.8

Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

CVE-2026-50329
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50326
HIGH 7.8

Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.

CVE-2026-50327
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

CVE-2026-50321
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv…

CVE-2026-50315
HIGH 7.8

Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

CVE-2026-50317
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to eleva…

CVE-2026-50309
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50313
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50305
HIGH 7.8

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50306
HIGH 7.8

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

CVE-2026-58609
HIGH 7.8

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

CVE-2026-58610
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVE-2026-58635
HIGH 7.8

Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privil…

CVE-2026-58601
HIGH 7.8

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58602
HIGH 7.8

Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-55004
HIGH 7.8

Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-54993
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVE-2026-54987
HIGH 7.8

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

CVE-2026-54991
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-54986
HIGH 7.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54112
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg…

CVE-2026-54114
HIGH 7.8

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54109
HIGH 7.8

Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-50697
HIGH 7.8

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50351
HIGH 7.8

Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.

CVE-2026-50311
HIGH 7.8

Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.

CVE-2026-50333
HIGH 7.8

Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-50318
HIGH 7.8

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50308
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-49808
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileg…

CVE-2026-50293
HIGH 7.8

Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.

CVE-2026-49800
HIGH 7.8

Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.

CVE-2026-49793
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-49796
HIGH 7.8

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

CVE-2026-49797
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-49792
HIGH 7.8

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-49783
HIGH 7.8

Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-49176
HIGH 7.8

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

CVE-2026-49175
HIGH 7.8

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-49173
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49166
HIGH 7.8

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-49170
HIGH 7.8

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVE-2026-42982
HIGH 7.8

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-44800
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-58531
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges …

CVE-2026-57089
HIGH 7.5

Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.

CVE-2026-56648
HIGH 7.5

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-50647
HIGH 7.5

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a n…

CVE-2026-50505
HIGH 7.5

Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.

CVE-2026-50500
HIGH 7.5

Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.

CVE-2026-50496
HIGH 7.5

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50470
HIGH 7.5

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50463
HIGH 7.5

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

CVE-2026-50424
HIGH 7.5

Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.

CVE-2026-50414
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50411
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVE-2026-50379
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50330
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-54983
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVE-2026-54119
HIGH 7.5

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

CVE-2026-50695
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

CVE-2026-50696
HIGH 7.5

Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

CVE-2026-49787
HIGH 7.5

Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVE-2026-49788
HIGH 7.5

Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.

CVE-2026-49171
HIGH 7.5

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVE-2026-40378
HIGH 7.5

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over …

CVE-2026-54127
HIGH 7.4

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

CVE-2026-50482
HIGH 7.3

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-58640
HIGH 7.3

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50364
HIGH 7.3

Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.

CVE-2026-49789
HIGH 7.3

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-49790
HIGH 7.3

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-58529
HIGH 7.1

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

CVE-2026-50682
HIGH 7.1

Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.

CVE-2026-50465
HIGH 7.1

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVE-2026-50451
HIGH 7.1

Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50428
HIGH 7.1

Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

CVE-2026-55144
HIGH 7.1

Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

CVE-2026-50354
HIGH 7.1

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49791
HIGH 7.1

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pri…

CVE-2026-49165
HIGH 7.1

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

CVE-2026-58598
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate p…

CVE-2026-58629
HIGH 7.0

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2026-58637
HIGH 7.0

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58619
HIGH 7.0

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58544
HIGH 7.0

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-57093
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-56183
HIGH 7.0

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-56187
HIGH 7.0

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-56173
HIGH 7.0

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

CVE-2026-50672
HIGH 7.0

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50674
HIGH 7.0

Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50669
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-50503
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50490
HIGH 7.0

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-50491
HIGH 7.0

Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-50459
HIGH 7.0

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

CVE-2026-50452
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi…

CVE-2026-50449
HIGH 7.0

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50410
HIGH 7.0

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50406
HIGH 7.0

Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

CVE-2026-50404
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50403
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50392
HIGH 7.0

Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-50393
HIGH 7.0

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-50396
HIGH 7.0

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-50397
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50390
HIGH 7.0

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50372
HIGH 7.0

Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.

CVE-2026-50371
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privilege…

CVE-2026-50359
HIGH 7.0

Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.

CVE-2026-50358
HIGH 7.0

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50348
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi…

CVE-2026-50345
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50322
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50307
HIGH 7.0

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

CVE-2026-58526
HIGH 7.0

Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-54996
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-54989
HIGH 7.0

Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.

CVE-2026-54129
HIGH 7.0

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-54111
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-50384
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate pr…

CVE-2026-50356
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele…

CVE-2026-50323
HIGH 7.0

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50325
HIGH 7.0

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-50297
HIGH 7.0

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-49806
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-50296
HIGH 7.0

Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49802
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-49805
HIGH 7.0

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-49803
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to…

CVE-2026-49784
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele…

CVE-2026-49183
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevat…

CVE-2026-48572
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p…

CVE-2026-48571
HIGH 7.0

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-49162
HIGH 7.0

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-58528
MEDIUM 6.8

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-50668
MEDIUM 6.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-50492
MEDIUM 6.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-54132
MEDIUM 6.8

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-50299
MEDIUM 6.8

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-50298
MEDIUM 6.8

Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-49168
MEDIUM 6.8

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-58546
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58539
MEDIUM 6.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58533
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58535
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-57982
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

CVE-2026-56168
MEDIUM 6.5

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVE-2026-54126
MEDIUM 6.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50504
MEDIUM 6.5

Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVE-2026-50497
MEDIUM 6.5

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

CVE-2026-50445
MEDIUM 6.5

Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50376
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50366
MEDIUM 6.5

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

CVE-2026-57976
MEDIUM 6.5

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

CVE-2026-57979
MEDIUM 6.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-55003
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-49799
MEDIUM 6.5

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

CVE-2026-34348
MEDIUM 6.5

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

CVE-2026-57097
MEDIUM 6.4

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-55000
MEDIUM 6.4

Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-58543
MEDIUM 6.3

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-50375
MEDIUM 6.3

Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2026-50374
MEDIUM 6.3

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.

CVE-2026-57095
MEDIUM 6.2

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

CVE-2026-50420
MEDIUM 6.2

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.

CVE-2026-50294
MEDIUM 6.2

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.

CVE-2026-49807
MEDIUM 6.2

Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.

CVE-2026-50661
MEDIUM 6.1

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-50495
MEDIUM 6.1

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVE-2026-50453
MEDIUM 6.1

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-50383
MEDIUM 6.1

Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

CVE-2026-49174
MEDIUM 6.1

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVE-2026-58638
MEDIUM 6.0

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

CVE-2026-56649
MEDIUM 5.9

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to e…

CVE-2026-58547
MEDIUM 5.5

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-58545
MEDIUM 5.5

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-57083
MEDIUM 5.5

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

CVE-2026-57084
MEDIUM 5.5

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

CVE-2026-57085
MEDIUM 5.5

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

CVE-2026-56184
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-50690
MEDIUM 5.5

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

CVE-2026-50681
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

CVE-2026-50483
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.

CVE-2026-50475
MEDIUM 5.5

Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50473
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-50455
MEDIUM 5.5

Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

CVE-2026-50456
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-50442
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-50434
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-50437
MEDIUM 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVE-2026-50430
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-50431
MEDIUM 5.5

Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability

CVE-2026-50409
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.

CVE-2026-50401
MEDIUM 5.5

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.

CVE-2026-50394
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

CVE-2026-50389
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-50377
MEDIUM 5.5

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50352
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

CVE-2026-50341
MEDIUM 5.5

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-50339
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-50334
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.

CVE-2026-49177
MEDIUM 5.5

Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.

CVE-2026-58614
MEDIUM 5.5

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-54997
MEDIUM 5.5

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

CVE-2026-50381
MEDIUM 5.5

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information local…

CVE-2026-50350
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information lo…

CVE-2026-50316
MEDIUM 5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50300
MEDIUM 5.5

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50303
MEDIUM 5.5

Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.

CVE-2026-50295
MEDIUM 5.5

Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.

CVE-2026-49801
MEDIUM 5.5

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

CVE-2026-49180
MEDIUM 5.5

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca…

CVE-2026-40422
MEDIUM 5.5

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-41087
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-34349
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

CVE-2026-34346
MEDIUM 5.5

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

CVE-2026-33842
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-34328
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

CVE-2026-50432
MEDIUM 5.3

Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.

CVE-2026-50415
MEDIUM 5.3

Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.

CVE-2026-44806
MEDIUM 5.3

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

CVE-2026-50418
MEDIUM 5.1

Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-50310
MEDIUM 4.7

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.

CVE-2026-50312
MEDIUM 4.7

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-49167
MEDIUM 4.7

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49794
MEDIUM 4.6

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-50485
MEDIUM 4.5

Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

CVE-2026-50302
MEDIUM 4.2

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-50419
LOW 3.3

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50416
LOW 3.3

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

Déployer ce correctif Windows sur votre flotte

Appaloosa pousse les mises à jour Windows et vérifie leur application sur tout votre parc.

Gérer Windows avec Appaloosa