Windows · Fixed build
10.0.26200.8875
MSRC advisory380 CVEs fixed by this build, deployed across 1 Windows SKUs.
- Published on
- 2026-07-16
- SKUs covered
- 1
- CVEs fixed
- 380
Windows SKUs covered by this build
The SKUs below share this MSRC build number. Deploying the corresponding KB secures all of them at once.
- CISA KEV
- 1
- Critical
- 9
- High
- 274
- NVD pending
- 0
CVEs fixed by this build
| CVE | Severity | KEV | Published | Description |
|---|---|---|---|---|
|
CVE-2026-32202
KEV
Windows Shell Spoofing Vulnerability |
HIGH 4.3 | KEV | Windows Shell Spoofing Vulnerability | |
|
CVE-2026-57092
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. |
CRITICAL 9.9 | — | Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-56190
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-56188
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network d… |
CRITICAL 9.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to… | |
|
CVE-2026-50447
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-54990
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-49172
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42990
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50380
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.6 | — | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-49798
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
CRITICAL 9.3 | — | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2026-58626
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
HIGH 8.8 | — | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | |
|
CVE-2026-58594
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. |
HIGH 8.8 | — | Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-58534
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges l… |
HIGH 8.8 | — | Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-57094
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a… |
HIGH 8.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-57090
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a… |
HIGH 8.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-57087
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a… |
HIGH 8.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-56647
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate… |
HIGH 8.8 | — | Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-56194
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a ne… |
HIGH 8.8 | — | Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50692
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50687
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50670
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50666
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a n… |
HIGH 8.8 | — | Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50489
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50474
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 8.8 | — | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50477
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50413
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50398
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an … |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… | |
|
CVE-2026-50385
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50382
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. |
HIGH 8.8 | — | Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. | |
|
CVE-2026-50369
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. |
HIGH 8.8 | — | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50360
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate pri… |
HIGH 8.8 | — | Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-58608
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Co… |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker t… | |
|
CVE-2026-54999
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an… |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o… | |
|
CVE-2026-54982
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker … |
HIGH 8.8 | — | Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | |
|
CVE-2026-54107
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an… |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg… | |
|
CVE-2026-50342
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49795
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49178
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a net… |
HIGH 8.8 | — | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | |
|
CVE-2026-50340
Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. |
HIGH 8.5 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-54128
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. |
HIGH 8.4 | — | Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-54992
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code loc… |
HIGH 8.4 | — | Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-54122
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
HIGH 8.4 | — | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-49184
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 8.4 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-56181
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofin… |
HIGH 8.3 | — | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | |
|
CVE-2026-50680
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
HIGH 8.2 | — | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50429
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. |
HIGH 8.2 | — | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-56186
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. |
HIGH 8.1 | — | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. | |
|
CVE-2026-50686
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute… |
HIGH 8.1 | — | Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50487
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. |
HIGH 8.1 | — | Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. | |
|
CVE-2026-50460
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 8.1 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… | |
|
CVE-2026-50439
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a networ… |
HIGH 8.1 | — | Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-54995
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a n… |
HIGH 8.1 | — | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50694
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over … |
HIGH 8.1 | — | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-49164
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a n… |
HIGH 8.1 | — | Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42900
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows… |
HIGH 8.1 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate pri… | |
|
CVE-2026-50502
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute co… |
HIGH 8.0 | — | Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. | |
|
CVE-2026-50365
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent netwo… |
HIGH 8.0 | — | Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. | |
|
CVE-2026-42975
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adj… |
HIGH 8.0 | — | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | |
|
CVE-2026-40400
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. |
HIGH 8.0 | — | Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | |
|
CVE-2026-58632
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58613
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58628
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Network… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to ele… | |
|
CVE-2026-58542
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-58538
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58540
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58541
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate p… |
HIGH 7.8 | — | Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58532
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58537
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges lo… |
HIGH 7.8 | — | Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58536
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58527
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-58530
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loca… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-57096
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-57091
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56650
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56643
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56644
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56189
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locall… |
HIGH 7.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-56182
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56176
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56175
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54125
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-54124
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-54115
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50689
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50688
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50677
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50679
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges lo… |
HIGH 7.8 | — | Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50673
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50676
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an … |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… | |
|
CVE-2026-50667
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an a… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges… | |
|
CVE-2026-50655
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50509
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevat… |
HIGH 7.8 | — | Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50501
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loc… |
HIGH 7.8 | — | Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50499
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges loca… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50498
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | |
|
CVE-2026-50493
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50494
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-50484
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50486
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50488
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service a… |
HIGH 7.8 | — | Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate … | |
|
CVE-2026-50476
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50478
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50471
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50469
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized at… |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50466
Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50462
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to… |
HIGH 7.8 | — | External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50461
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50454
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50457
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50458
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50448
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50450
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Ar… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized … | |
|
CVE-2026-50440
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service al… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate p… | |
|
CVE-2026-50441
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileg… |
HIGH 7.8 | — | Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50433
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50436
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50435
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50427
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50425
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50423
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50422
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50421
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allow… |
HIGH 7.8 | — | Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate priv… | |
|
CVE-2026-50412
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50417
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-50407
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges … |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50405
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate… |
HIGH 7.8 | — | Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50400
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50402
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50399
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50391
Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50386
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50388
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50387
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50378
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privi… | |
|
CVE-2026-50373
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges local… |
HIGH 7.8 | — | Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50367
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to … |
HIGH 7.8 | — | Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50363
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50361
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50362
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loca… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50357
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | |
|
CVE-2026-50353
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50347
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50346
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50344
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50337
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50343
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50336
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50332
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50331
Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50335
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50329
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50326
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50327
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | |
|
CVE-2026-50321
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allow… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv… | |
|
CVE-2026-50315
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50317
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating System… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to eleva… | |
|
CVE-2026-50309
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-50313
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50305
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50306
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58609
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-58610
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locall… |
HIGH 7.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-58635
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows … |
HIGH 7.8 | — | Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privil… | |
|
CVE-2026-58601
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileg… |
HIGH 7.8 | — | Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58602
Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-55004
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54993
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locall… |
HIGH 7.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-54987
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54991
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-54986
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54112
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg… | |
|
CVE-2026-54114
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54109
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code lo… |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | |
|
CVE-2026-50697
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorize… |
HIGH 7.8 | — | Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50351
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges … |
HIGH 7.8 | — | Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50311
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50333
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileg… |
HIGH 7.8 | — | Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50318
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges… |
HIGH 7.8 | — | Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50308
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-49808
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileg… | |
|
CVE-2026-50293
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49800
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to ele… |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49793
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locall… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | |
|
CVE-2026-49796
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-49797
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-49792
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | |
|
CVE-2026-49783
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a sec… |
HIGH 7.8 | — | Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-49176
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49175
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49166
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49170
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate priv… |
HIGH 7.8 | — | Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42982
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate … |
HIGH 7.8 | — | Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-44800
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notificatio… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… | |
|
CVE-2026-58531
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an au… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges … | |
|
CVE-2026-57089
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute c… |
HIGH 7.5 | — | Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-56648
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to eleva… |
HIGH 7.5 | — | Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50647
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauth… |
HIGH 7.5 | — | Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a n… | |
|
CVE-2026-50505
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. |
HIGH 7.5 | — | Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. | |
|
CVE-2026-50500
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. |
HIGH 7.5 | — | Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50496
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a… |
HIGH 7.5 | — | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50470
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a… |
HIGH 7.5 | — | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50463
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. |
HIGH 7.5 | — | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50424
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a netwo… |
HIGH 7.5 | — | Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50414
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an … |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… | |
|
CVE-2026-50411
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny ser… |
HIGH 7.5 | — | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50379
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an … |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… | |
|
CVE-2026-50330
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a networ… |
HIGH 7.5 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. | |
|
CVE-2026-54983
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny ser… |
HIGH 7.5 | — | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-54119
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to d… |
HIGH 7.5 | — | Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50695
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service ove… |
HIGH 7.5 | — | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50696
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny serv… |
HIGH 7.5 | — | Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-49787
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny servic… |
HIGH 7.5 | — | Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-49788
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a n… |
HIGH 7.5 | — | Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-49171
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
HIGH 7.5 | — | Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-40378
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an una… |
HIGH 7.5 | — | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over … | |
|
CVE-2026-54127
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. |
HIGH 7.4 | — | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2026-50482
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.3 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-58640
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.3 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-50364
Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker t… |
HIGH 7.3 | — | Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49789
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.3 | — | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49790
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | |
|
CVE-2026-50682
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. |
HIGH 7.1 | — | Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. | |
|
CVE-2026-50465
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
HIGH 7.1 | — | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | |
|
CVE-2026-50451
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized a… |
HIGH 7.1 | — | Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-55144
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. |
HIGH 7.1 | — | Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. | |
|
CVE-2026-50354
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.1 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49791
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allo… |
HIGH 7.1 | — | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pri… | |
|
CVE-2026-49165
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information loca… |
HIGH 7.1 | — | Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally. | |
|
CVE-2026-58598
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine al… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate p… | |
|
CVE-2026-58629
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58637
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58619
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58544
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-57093
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56183
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56187
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56173
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50672
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50674
Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50669
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Servic… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… | |
|
CVE-2026-50503
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50490
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50491
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50459
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2026-50452
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… | |
|
CVE-2026-50449
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50410
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50406
Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50404
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an … |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… | |
|
CVE-2026-50403
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50392
Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50393
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50396
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50397
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50390
Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevat… |
HIGH 7.0 | — | Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50372
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50371
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an … |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privilege… | |
|
CVE-2026-50359
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50358
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50348
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… | |
|
CVE-2026-50345
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50322
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50307
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58526
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54996
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-54989
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privi… |
HIGH 7.0 | — | Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54129
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54111
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-50384
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service all… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate pr… | |
|
CVE-2026-50356
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App St… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele… | |
|
CVE-2026-50323
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50325
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50297
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49806
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-50296
Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49802
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-49805
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49803
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment … |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to… | |
|
CVE-2026-49784
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App St… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele… | |
|
CVE-2026-49183
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevat… | |
|
CVE-2026-48572
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer al… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p… | |
|
CVE-2026-48571
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49162
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58528
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informa… |
MEDIUM 6.8 | — | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | |
|
CVE-2026-50668
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. |
MEDIUM 6.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-50492
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with… |
MEDIUM 6.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. | |
|
CVE-2026-54132
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical atta… |
MEDIUM 6.8 | — | Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-50299
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a … |
MEDIUM 6.8 | — | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. | |
|
CVE-2026-50298
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a ph… |
MEDIUM 6.8 | — | Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-49168
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges w… |
MEDIUM 6.8 | — | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-49804
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a phy… |
MEDIUM 6.6 | — | Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-58546
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-58539
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-58533
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-58535
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-57982
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. | |
|
CVE-2026-56168
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. |
MEDIUM 6.5 | — | Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. | |
|
CVE-2026-54126
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50504
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50497
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a netw… |
MEDIUM 6.5 | — | Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50445
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50376
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50366
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a netwo… |
MEDIUM 6.5 | — | Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. | |
|
CVE-2026-57976
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a netwo… |
MEDIUM 6.5 | — | Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. | |
|
CVE-2026-57979
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-55003
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-49799
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized at… |
MEDIUM 6.5 | — | Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. | |
|
CVE-2026-34348
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information ove… |
MEDIUM 6.5 | — | Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. | |
|
CVE-2026-57097
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical att… |
MEDIUM 6.4 | — | Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. | |
|
CVE-2026-55000
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
MEDIUM 6.4 | — | Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-58543
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
MEDIUM 6.3 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-50375
Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.3 | — | Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50374
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a phy… |
MEDIUM 6.3 | — | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-57095
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate… |
MEDIUM 6.2 | — | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2026-50420
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally. |
MEDIUM 6.2 | — | Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-50294
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized att… |
MEDIUM 6.2 | — | Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-49807
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclo… |
MEDIUM 6.2 | — | Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-50661
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a p… |
MEDIUM 6.1 | — | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | |
|
CVE-2026-50495
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
MEDIUM 6.1 | — | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | |
|
CVE-2026-50453
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informa… |
MEDIUM 6.1 | — | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | |
|
CVE-2026-50383
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
MEDIUM 6.1 | — | Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | |
|
CVE-2026-49174
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tamperin… |
MEDIUM 6.1 | — | Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | |
|
CVE-2026-58638
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. |
MEDIUM 6.0 | — | Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-56649
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File Sys… |
MEDIUM 5.9 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to e… | |
|
CVE-2026-58547
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges lo… |
MEDIUM 5.5 | — | Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58545
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
MEDIUM 5.5 | — | Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-57083
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose informati… |
MEDIUM 5.5 | — | Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-57084
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-57085
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | |
|
CVE-2026-56184
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50690
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50681
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attac… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50483
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacke… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50475
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50473
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50455
Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose informati… |
MEDIUM 5.5 | — | Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50456
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50442
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50434
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50437
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50430
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50431
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability |
MEDIUM 5.5 | — | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability | |
|
CVE-2026-50409
Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to d… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50401
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information loca… |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50394
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose i… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50389
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50377
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50352
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attac… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50341
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50339
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50334
Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to dis… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally. | |
|
CVE-2026-49177
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. | |
|
CVE-2026-58614
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-54997
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50381
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorize… |
MEDIUM 5.5 | — | Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information local… | |
|
CVE-2026-50350
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an author… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information lo… | |
|
CVE-2026-50316
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose informatio… |
MEDIUM 5.5 | — | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50300
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50303
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypa… |
MEDIUM 5.5 | — | Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-50295
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature local… |
MEDIUM 5.5 | — | Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-49801
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | |
|
CVE-2026-49180
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authoriz… |
MEDIUM 5.5 | — | Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca… | |
|
CVE-2026-40422
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-41087
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-34349
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose i… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. | |
|
CVE-2026-34346
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized a… |
MEDIUM 5.5 | — | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | |
|
CVE-2026-33842
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-34328
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50432
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. |
MEDIUM 5.3 | — | Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. | |
|
CVE-2026-50415
Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose… |
MEDIUM 5.3 | — | Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-44806
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to… |
MEDIUM 5.3 | — | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50418
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. |
MEDIUM 5.1 | — | Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. | |
|
CVE-2026-50310
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information… |
MEDIUM 4.7 | — | Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50312
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
MEDIUM 4.7 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49167
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
MEDIUM 4.7 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49794
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informa… |
MEDIUM 4.6 | — | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | |
|
CVE-2026-50485
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. |
MEDIUM 4.5 | — | Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | |
|
CVE-2026-50302
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security … |
MEDIUM 4.2 | — | Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network. | |
|
CVE-2026-50419
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose … |
LOW 3.3 | — | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50416
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose … |
LOW 3.3 | — | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. |