CVE-2026-58547
Last Modified: 7 Aug 2026Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-58536
Last Modified: 7 Aug 2026Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58534
Last Modified: 7 Aug 2026Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2026-58537
Last Modified: 7 Aug 2026Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-58532
Last Modified: 7 Aug 2026Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-58531
Last Modified: 7 Aug 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVE-2026-58540
Last Modified: 7 Aug 2026Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-58539
Last Modified: 7 Aug 2026Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58546
Last Modified: 7 Aug 2026Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58535
Last Modified: 7 Aug 2026Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58533
Last Modified: 7 Aug 2026Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58538
Last Modified: 7 Aug 2026Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58530
Last Modified: 7 Aug 2026Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
CVE-2026-58528
Last Modified: 7 Aug 2026Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-58527
Last Modified: 7 Aug 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-58277
Last Modified: 14 Jul 2026Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-57982
Last Modified: 7 Aug 2026Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
CVE-2026-57973
Last Modified: 15 Jul 2026Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.
CVE-2026-57968
Last Modified: 14 Jul 2026Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
CVE-2026-57108
Last Modified: 17 Jul 2026Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57102
Last Modified: 14 Jul 2026Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-57101
Last Modified: 14 Jul 2026Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-57096
Last Modified: 7 Aug 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-57093
Last Modified: 7 Aug 2026Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-57088
Last Modified: 7 Aug 2026Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
CVE-2026-57087
Last Modified: 7 Aug 2026Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-57092
Last Modified: 7 Aug 2026Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
CVE-2026-57085
Last Modified: 7 Aug 2026Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVE-2026-57089
Last Modified: 7 Aug 2026Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
CVE-2026-57091
Last Modified: 7 Aug 2026Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.
CVE-2026-57094
Last Modified: 7 Aug 2026Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-57090
Last Modified: 7 Aug 2026Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-57095
Last Modified: 7 Aug 2026Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
CVE-2026-56650
Last Modified: 7 Aug 2026Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
CVE-2026-57084
Last Modified: 7 Aug 2026Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
CVE-2026-57083
Last Modified: 7 Aug 2026Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
CVE-2026-56649
Last Modified: 7 Aug 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.
CVE-2026-56648
Last Modified: 7 Aug 2026Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.
CVE-2026-56647
Last Modified: 7 Aug 2026Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
CVE-2026-56194
Last Modified: 7 Aug 2026Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
CVE-2026-54124
Last Modified: 7 Aug 2026Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
CVE-2026-56644
Last Modified: 7 Aug 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56643
Last Modified: 7 Aug 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56642
Last Modified: 15 Jul 2026Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
CVE-2026-56178
Last Modified: 14 Jul 2026Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2026-56197
Last Modified: 14 Jul 2026Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-56196
Last Modified: 14 Jul 2026Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-56195
Last Modified: 14 Jul 2026Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56192
Last Modified: 7 Aug 2026Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-50665
Last Modified: 15 Jul 2026Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
