CVE-2026-50304
Last Modified: 22 Jul 2026Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-50392
Last Modified: 15 Jul 2026Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-50363
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-50329
Last Modified: 15 Jul 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50305
Last Modified: 15 Jul 2026Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50372
Last Modified: 15 Jul 2026Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
CVE-2026-50332
Last Modified: 14 Jul 2026Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50302
Last Modified: 15 Jul 2026Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50364
Last Modified: 14 Jul 2026Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.
CVE-2026-50303
Last Modified: 14 Jul 2026Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.
CVE-2026-50300
Last Modified: 16 Jul 2026Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50381
Last Modified: 15 Jul 2026Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.
CVE-2026-50350
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
CVE-2026-50295
Last Modified: 14 Jul 2026Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
CVE-2026-50384
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50356
Last Modified: 14 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
CVE-2026-50325
Last Modified: 14 Jul 2026Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50297
Last Modified: 14 Jul 2026Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50296
Last Modified: 14 Jul 2026Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50354
Last Modified: 15 Jul 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50316
Last Modified: 15 Jul 2026Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50293
Last Modified: 15 Jul 2026Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.
CVE-2026-49808
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50298
Last Modified: 15 Jul 2026Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-50342
Last Modified: 15 Jul 2026Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-49807
Last Modified: 14 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.
CVE-2026-50351
Last Modified: 16 Jul 2026Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
CVE-2026-50318
Last Modified: 15 Jul 2026Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-50323
Last Modified: 15 Jul 2026Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-49803
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
CVE-2026-49805
Last Modified: 14 Jul 2026Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-49806
Last Modified: 14 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-49802
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-49801
Last Modified: 14 Jul 2026Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVE-2026-50333
Last Modified: 14 Jul 2026Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-50294
Last Modified: 16 Jul 2026Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.
CVE-2026-49804
Last Modified: 16 Jul 2026Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-50311
Last Modified: 14 Jul 2026Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
CVE-2026-50308
Last Modified: 14 Jul 2026Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-49799
Last Modified: 14 Jul 2026Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
CVE-2026-49800
Last Modified: 14 Jul 2026Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
CVE-2026-50299
Last Modified: 15 Jul 2026Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-49798
Last Modified: 15 Jul 2026Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2026-49797
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-49795
Last Modified: 14 Jul 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49796
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
CVE-2026-49794
Last Modified: 14 Jul 2026Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-49793
Last Modified: 14 Jul 2026Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-49792
Last Modified: 15 Jul 2026Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-49791
Last Modified: 15 Jul 2026Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
