CVE-2026-50486
Last Modified: 14 Jul 2026Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50485
Last Modified: 14 Jul 2026Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2026-50502
Last Modified: 15 Jul 2026Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
CVE-2026-50493
Last Modified: 14 Jul 2026Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50484
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50483
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.
CVE-2026-50495
Last Modified: 15 Jul 2026Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
CVE-2026-50482
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50480
Last Modified: 14 Jul 2026Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
CVE-2026-50479
Last Modified: 14 Jul 2026Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50478
Last Modified: 16 Jul 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50477
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50459
Last Modified: 14 Jul 2026Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50470
Last Modified: 15 Jul 2026Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50406
Last Modified: 15 Jul 2026Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
CVE-2026-50424
Last Modified: 14 Jul 2026Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.
CVE-2026-50450
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50429
Last Modified: 15 Jul 2026Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
CVE-2026-50476
Last Modified: 15 Jul 2026Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.
CVE-2026-50475
Last Modified: 16 Jul 2026Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50458
Last Modified: 15 Jul 2026Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50415
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.
CVE-2026-50394
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
CVE-2026-50444
Last Modified: 15 Jul 2026Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-50411
Last Modified: 22 Jul 2026Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CVE-2026-50474
Last Modified: 14 Jul 2026Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-50362
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
CVE-2026-50420
Last Modified: 16 Jul 2026Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.
CVE-2026-50438
Last Modified: 15 Jul 2026Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-50447
Last Modified: 14 Jul 2026Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-15747
Last Modified: 27 Jul 2026Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle. An attacker able to query it can recover the token and pass csrf_protect validation.
CVE-2026-50417
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50453
Last Modified: 14 Jul 2026Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-50431
Last Modified: 15 Jul 2026Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
CVE-2026-50461
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50399
Last Modified: 15 Jul 2026Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50432
Last Modified: 14 Jul 2026Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
CVE-2026-50456
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50389
Last Modified: 16 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50442
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50473
Last Modified: 14 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50457
Last Modified: 15 Jul 2026Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50462
Last Modified: 15 Jul 2026External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-50439
Last Modified: 15 Jul 2026Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
CVE-2026-50465
Last Modified: 16 Jul 2026Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
CVE-2026-50441
Last Modified: 15 Jul 2026Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-50409
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.
CVE-2026-50435
Last Modified: 15 Jul 2026Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
CVE-2026-50402
Last Modified: 15 Jul 2026Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50466
Last Modified: 15 Jul 2026Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.
