CVE-2026-50455
Last Modified: 15 Jul 2026Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVE-2026-50451
Last Modified: 15 Jul 2026Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-50383
Last Modified: 15 Jul 2026Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVE-2026-50367
Last Modified: 15 Jul 2026Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50374
Last Modified: 15 Jul 2026Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.
CVE-2026-50421
Last Modified: 15 Jul 2026Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
CVE-2026-50422
Last Modified: 14 Jul 2026Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50427
Last Modified: 15 Jul 2026Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-50413
Last Modified: 15 Jul 2026Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50385
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50426
Last Modified: 29 Jul 2026Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
CVE-2026-50365
Last Modified: 14 Jul 2026Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
CVE-2026-50454
Last Modified: 29 Jul 2026Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
CVE-2026-50469
Last Modified: 15 Jul 2026Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50369
Last Modified: 15 Jul 2026Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
CVE-2026-50471
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50437
Last Modified: 15 Jul 2026Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-50436
Last Modified: 15 Jul 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50382
Last Modified: 15 Jul 2026Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
CVE-2026-50352
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
CVE-2026-50344
Last Modified: 15 Jul 2026Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
CVE-2026-50445
Last Modified: 15 Jul 2026Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50334
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.
CVE-2026-50387
Last Modified: 15 Jul 2026Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-50448
Last Modified: 14 Jul 2026Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50405
Last Modified: 15 Jul 2026Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
CVE-2026-50397
Last Modified: 15 Jul 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50376
Last Modified: 15 Jul 2026Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50346
Last Modified: 15 Jul 2026Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50401
Last Modified: 15 Jul 2026Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
CVE-2026-50378
Last Modified: 16 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.
CVE-2026-50423
Last Modified: 15 Jul 2026Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50418
Last Modified: 15 Jul 2026Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-50391
Last Modified: 14 Jul 2026Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.
CVE-2026-50433
Last Modified: 15 Jul 2026Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50403
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50460
Last Modified: 14 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50463
Last Modified: 15 Jul 2026Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
CVE-2026-50379
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
CVE-2026-50414
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
CVE-2026-50398
Last Modified: 14 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
CVE-2026-50336
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50371
Last Modified: 14 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.
CVE-2026-50449
Last Modified: 15 Jul 2026Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50410
Last Modified: 14 Jul 2026Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50388
Last Modified: 15 Jul 2026Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50353
Last Modified: 15 Jul 2026Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-50373
Last Modified: 15 Jul 2026Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2026-50428
Last Modified: 14 Jul 2026Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
CVE-2026-50355
Last Modified: 22 Jul 2026Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
