CVE-2026-49790
Last Modified: 15 Jul 2026Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-49789
Last Modified: 14 Jul 2026Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-49788
Last Modified: 14 Jul 2026Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
CVE-2026-49787
Last Modified: 14 Jul 2026Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
CVE-2026-49783
Last Modified: 15 Jul 2026Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-49183
Last Modified: 14 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
CVE-2026-49184
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-49181
Last Modified: 29 Jul 2026Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-49180
Last Modified: 14 Jul 2026Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVE-2026-49178
Last Modified: 15 Jul 2026Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
CVE-2026-45646
Last Modified: 14 Jul 2026Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-48581
Last Modified: 14 Jul 2026Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
CVE-2026-48564
Last Modified: 15 Jul 2026Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVE-2026-47632
Last Modified: 18 Aug 2026Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
CVE-2026-44800
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-40378
Last Modified: 14 Jul 2026Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
CVE-2026-44806
Last Modified: 14 Jul 2026Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
CVE-2026-34348
Last Modified: 16 Jul 2026Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
CVE-2026-40400
Last Modified: 14 Jul 2026Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
CVE-2026-41087
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-40422
Last Modified: 15 Jul 2026Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-34328
Last Modified: 15 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
CVE-2026-33842
Last Modified: 14 Jul 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50653
Last Modified: 22 Jul 2026Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-50652
Last Modified: 22 Jul 2026Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-58647
Last Modified: 15 Jul 2026Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
CVE-2026-58644
Last Modified: 16 Jul 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-58640
Last Modified: 14 Jul 2026Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-58636
Last Modified: 14 Jul 2026Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58635
Last Modified: 15 Jul 2026Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CVE-2026-58631
Last Modified: 14 Jul 2026Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
CVE-2026-58618
Last Modified: 15 Jul 2026Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-58614
Last Modified: 16 Jul 2026Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
CVE-2026-58610
Last Modified: 14 Jul 2026Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
CVE-2026-58609
Last Modified: 14 Jul 2026Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
CVE-2026-58608
Last Modified: 15 Jul 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
CVE-2026-58602
Last Modified: 14 Jul 2026Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58601
Last Modified: 14 Jul 2026Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50522
Last Modified: 22 Jul 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-58595
Last Modified: 16 Jul 2026Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58526
Last Modified: 14 Jul 2026Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-58279
Last Modified: 14 Jul 2026Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
CVE-2026-55014
Last Modified: 15 Jul 2026Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
CVE-2026-57979
Last Modified: 15 Jul 2026Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-57976
Last Modified: 14 Jul 2026Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
CVE-2026-57969
Last Modified: 15 Jul 2026Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
CVE-2026-57107
Last Modified: 15 Jul 2026Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
CVE-2026-57097
Last Modified: 14 Jul 2026Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-56185
Last Modified: 15 Jul 2026Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
CVE-2026-56193
Last Modified: 14 Jul 2026Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
