CVE-2026-20871
Last Modified: 16 Apr 2026Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-20870
Last Modified: 18 Apr 2026Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2026-20868
Last Modified: 16 Apr 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2026-20867
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20866
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20863
Last Modified: 16 Apr 2026Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2026-20862
Last Modified: 16 Apr 2026Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.
CVE-2026-20861
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-21219
Last Modified: 16 Apr 2026Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2026-20854
Last Modified: 16 Apr 2026Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.
CVE-2026-20853
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.
CVE-2026-20849
Last Modified: 16 Apr 2026Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVE-2026-20848
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-20843
Last Modified: 16 Apr 2026Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-20947
Last Modified: 16 Apr 2026Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-21224
Last Modified: 16 Apr 2026Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-21221
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-20830
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-20963
Last Modified: 2 Apr 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-20959
Last Modified: 16 Apr 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-20956
Last Modified: 16 Apr 2026Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20955
Last Modified: 16 Apr 2026Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20953
Last Modified: 16 Apr 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20951
Last Modified: 16 Apr 2026Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
CVE-2026-20946
Last Modified: 16 Apr 2026Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20944
Last Modified: 16 Apr 2026Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20943
Last Modified: 16 Apr 2026Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20940
Last Modified: 16 Apr 2026Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-20938
Last Modified: 30 Jul 2026Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
CVE-2026-20934
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-20932
Last Modified: 16 Apr 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-20927
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
CVE-2026-20926
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-20925
Last Modified: 16 Apr 2026External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20924
Last Modified: 16 Apr 2026Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20923
Last Modified: 16 Apr 2026Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20922
Last Modified: 16 Apr 2026Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-20921
Last Modified: 26 May 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-20920
Last Modified: 18 Apr 2026Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2026-20919
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-20918
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20877
Last Modified: 18 Apr 2026Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20876
Last Modified: 16 Apr 2026Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
CVE-2026-20875
Last Modified: 16 Apr 2026Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
CVE-2026-20869
Last Modified: 16 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.
CVE-2026-20865
Last Modified: 16 Apr 2026Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20864
Last Modified: 26 May 2026Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-20860
Last Modified: 16 Apr 2026Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-20859
Last Modified: 18 Apr 2026Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-20858
Last Modified: 16 Apr 2026Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
