CVE-2026-62761
Last Modified: 17 Aug 2026Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62771
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62769
Last Modified: 17 Aug 2026Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62752
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
CVE-2026-62751
Last Modified: 14 Aug 2026Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-62749
Last Modified: 14 Aug 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-62741
Last Modified: 14 Aug 2026Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-62757
Last Modified: 14 Aug 2026Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62736
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
CVE-2026-62734
Last Modified: 18 Aug 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62732
Last Modified: 18 Aug 2026Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62730
Last Modified: 14 Aug 2026Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
CVE-2026-62743
Last Modified: 14 Aug 2026Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-20349
Last Modified: 12 Aug 2026A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
CVE-2026-62733
Last Modified: 14 Aug 2026Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62728
Last Modified: 14 Aug 2026Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62726
Last Modified: 18 Aug 2026Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62725
Last Modified: 18 Aug 2026Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62721
Last Modified: 14 Aug 2026Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
CVE-2026-62717
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2026-62714
Last Modified: 14 Aug 2026Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62720
Last Modified: 14 Aug 2026Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62711
Last Modified: 14 Aug 2026Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62710
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62709
Last Modified: 14 Aug 2026Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
CVE-2026-62708
Last Modified: 14 Aug 2026Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-62701
Last Modified: 14 Aug 2026Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62700
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-62698
Last Modified: 14 Aug 2026Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.
CVE-2026-61938
Last Modified: 17 Aug 2026Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-61929
Last Modified: 14 Aug 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-61921
Last Modified: 14 Aug 2026Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61918
Last Modified: 14 Aug 2026Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61926
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-61920
Last Modified: 2 Sept 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.
CVE-2026-61360
Last Modified: 14 Aug 2026Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-61358
Last Modified: 14 Aug 2026Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
CVE-2026-61357
Last Modified: 14 Aug 2026Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61365
Last Modified: 14 Aug 2026Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61364
Last Modified: 14 Aug 2026Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61355
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61359
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-61363
Last Modified: 14 Aug 2026Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-61349
Last Modified: 14 Aug 2026Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CVE-2026-59131
Last Modified: 25 Aug 2026No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
CVE-2026-59126
Last Modified: 14 Aug 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CVE-2026-59125
Last Modified: 14 Aug 2026Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-59122
Last Modified: 14 Aug 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-59119
Last Modified: 17 Aug 2026Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2026-58651
Last Modified: 14 Aug 2026Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
