CVE-2026-32088
Last Modified: 24 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-32086
Last Modified: 24 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-32084
Last Modified: 24 Apr 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-32080
Last Modified: 24 Apr 2026Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.
CVE-2026-32079
Last Modified: 24 Apr 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-32078
Last Modified: 24 Apr 2026Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-32077
Last Modified: 26 May 2026Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
CVE-2026-32076
Last Modified: 24 Apr 2026Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
CVE-2026-32074
Last Modified: 24 Apr 2026Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-32072
Last Modified: 24 Apr 2026Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
CVE-2026-32070
Last Modified: 24 Apr 2026Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-32069
Last Modified: 24 Apr 2026Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-32068
Last Modified: 24 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
CVE-2026-27930
Last Modified: 24 Apr 2026Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
CVE-2026-27928
Last Modified: 24 Apr 2026Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-27925
Last Modified: 24 Apr 2026Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-27923
Last Modified: 24 Apr 2026Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-27922
Last Modified: 24 Apr 2026Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-27920
Last Modified: 24 Apr 2026Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
CVE-2026-27916
Last Modified: 24 Apr 2026Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
CVE-2026-27914
Last Modified: 24 Apr 2026Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
CVE-2026-27913
Last Modified: 24 Apr 2026Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-27912
Last Modified: 24 Apr 2026Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
CVE-2026-27911
Last Modified: 24 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
CVE-2026-27910
Last Modified: 24 Apr 2026Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-27909
Last Modified: 24 Apr 2026Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2026-26184
Last Modified: 24 Apr 2026Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-26182
Last Modified: 24 Apr 2026Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-26178
Last Modified: 24 Apr 2026Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-26177
Last Modified: 24 Apr 2026Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-26176
Last Modified: 24 Apr 2026Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally.
CVE-2026-26173
Last Modified: 24 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-26172
Last Modified: 24 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-26170
Last Modified: 24 Apr 2026Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2026-26169
Last Modified: 24 Apr 2026Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
CVE-2026-26168
Last Modified: 24 Apr 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-26163
Last Modified: 24 Apr 2026Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-26159
Last Modified: 24 Apr 2026Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
CVE-2026-26156
Last Modified: 24 Apr 2026Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.
CVE-2026-26153
Last Modified: 24 Apr 2026Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-26152
Last Modified: 24 Apr 2026Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
CVE-2026-26143
Last Modified: 27 Apr 2026Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-23666
Last Modified: 7 May 2026Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-23657
Last Modified: 29 Apr 2026Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20806
Last Modified: 24 Apr 2026Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
CVE-2026-20928
Last Modified: 24 Apr 2026Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-32212
Last Modified: 24 Apr 2026Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVE-2026-33826
Last Modified: 24 Apr 2026Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
CVE-2026-33825
Last Modified: 24 Apr 2026Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVE-2026-33822
Last Modified: 29 Apr 2026Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
