← Browse

Microsoft

300 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-13445 HIGH 8.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component … 2026-07-17 CVE-2026-13446 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key… 2026-07-17 CVE-2026-13448 HIGH 8.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerabil… 2026-07-17 CVE-2026-14499 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands… 2026-07-17 CVE-2026-56171 HIGH 7.1 Remote Desktop Web Client — Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attack… 2026-07-17 CVE-2026-57980 MEDIUM 5.4 Microsoft Edge (Chromium Based) — Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthor… 2026-07-17 CVE-2026-7667 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to … 2026-07-17 CVE-2026-7754 HIGH 7.7 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to ins… 2026-07-17 CVE-2026-7755 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation … 2026-07-17 CVE-2026-7872 HIGH 7.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the J… 2026-07-17 CVE-2026-8056 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime v… 2026-07-17 CVE-2026-8476 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based… 2026-07-17 CVE-2026-8481 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code valid… 2026-07-17 CVE-2026-8505 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows un… 2026-07-17 CVE-2026-8635 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by direct… 2026-07-17 CVE-2026-8859 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended … 2026-07-17 CVE-2026-9103 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to imprope… 2026-07-17 CVE-2026-9135 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc… 2026-07-17 CVE-2026-53597 HIGH 8.7 Prompty — Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prom… 2026-07-16 CVE-2026-53598 HIGH 7.5 Prompty — Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded … 2026-07-16 CVE-2026-54568 MEDIUM 4.3 Ufo — Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until …● PoC 2026-07-16 CVE-2026-54733 CRITICAL 9.3 O365 Moodle — The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory inte… 2026-07-16 CVE-2026-55440 MEDIUM 6.5 Ufo — Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, t…● PoC 2026-07-16 CVE-2026-57205 MEDIUM 4.3 Simplechat — SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded in… 2026-07-16 CVE-2026-57206 HIGH 8.6 Simplechat — SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded in… 2026-07-16 CVE-2026-58598 HIGH 7 Windows 10 Version 21h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup … 2026-07-16 CVE-2026-58643 MEDIUM 6.1 Windows Admin Center — Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center a… 2026-07-16 CVE-2026-59117 HIGH 7.5 Windows Terminal App — Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a netw… 2026-07-16 CVE-2026-59859 HIGH 8.7 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI … 2026-07-16 CVE-2026-59860 HIGH 8.7 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation …● PoC 2026-07-16 CVE-2026-59861 HIGH 7.5 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI… 2026-07-16 CVE-2026-59862 HIGH 7.5 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-c… 2026-07-16 CVE-2026-59863 HIGH 7 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspa… 2026-07-16 CVE-2026-59864 CRITICAL 9.3 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin ge… 2026-07-16 CVE-2026-59865 CRITICAL 9.3 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.langu… 2026-07-16 CVE-2026-59866 CRITICAL 9.3 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientCla… 2026-07-16 CVE-2026-59867 HIGH 7.1 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by f… 2026-07-16 CVE-2026-62826 MEDIUM 4.6 Microsoft Sharepoint Enterprise Server 2016 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share… 2026-07-16 CVE-2026-40952 HIGH 8.5 Secure Access — CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and serve… 2026-07-15 CVE-2026-11944 MEDIUM 5.3 Opensis Classic — openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail a…● PoC 2026-07-14 CVE-2026-15767 HIGH 8.8 Chrome — Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker t… 2026-07-14 CVE-2026-15771 MEDIUM 5.3 Chrome — Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowe… 2026-07-14 CVE-2026-15773 CRITICAL 9.6 Chrome — Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potent… 2026-07-14 CVE-2026-33842 MEDIUM 5.5 Windows 10 Version 1607 — Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attac… 2026-07-14 CVE-2026-34328 MEDIUM 5.5 Windows 10 Version 1809 — Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attac… 2026-07-14 CVE-2026-34346 MEDIUM 5.5 Windows 10 Version 1607 — Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an aut… 2026-07-14 CVE-2026-34348 MEDIUM 6.5 Windows 10 Version 1809 — Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose inform… 2026-07-14 CVE-2026-34349 MEDIUM 5.5 Windows 10 Version 1809 — Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to d… 2026-07-14 CVE-2026-40378 HIGH 7.5 Windows 10 Version 1607 — Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allo… 2026-07-14 CVE-2026-40400 HIGH 8 Windows 10 Version 1607 — Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. 2026-07-14 CVE-2026-40422 MEDIUM 5.5 Windows 10 Version 1607 — Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information l… 2026-07-14 CVE-2026-41087 MEDIUM 5.5 Windows 10 Version 1607 — Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attac… 2026-07-14 CVE-2026-42900 HIGH 8.1 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Sto… 2026-07-14 CVE-2026-42975 HIGH 8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code ov… 2026-07-14 CVE-2026-42982 HIGH 7.8 Windows 10 Version 1607 — Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to… 2026-07-14 CVE-2026-42990 CRITICAL 9.8 Windows 10 Version 1607 — Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a ne… 2026-07-14 CVE-2026-44800 HIGH 7.8 Windows 11 Version 23h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push No… 2026-07-14 CVE-2026-44806 MEDIUM 5.3 Windows 10 Version 1607 — Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized at… 2026-07-14 CVE-2026-45496 MEDIUM 5.5 Visual Studio Code — Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an… 2026-07-14 CVE-2026-45646 HIGH 7.5 Aspnet.Odata — Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny s… 2026-07-14 CVE-2026-47282 MEDIUM 6.5 Visual Studio Code — Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker … 2026-07-14 CVE-2026-47290 HIGH 7.8 Microsoft 365 Apps For Enterprise — Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-47295 HIGH 8.8 Microsoft Sql Server 2016 Service Pack 3 (Gdr) — Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an a… 2026-07-14 CVE-2026-47296 HIGH 7.8 Microsoft Sql Server 2016 Service Pack 3 (Gdr) — Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an a… 2026-07-14 CVE-2026-47300 HIGH 8.8 .Net 10.0 — Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate … 2026-07-14 CVE-2026-47301 HIGH 8.8 Microsoft Configuration Manager — Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges… 2026-07-14 CVE-2026-47302 HIGH 7.5 .Net 10.0 — Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service o… 2026-07-14 CVE-2026-47303 HIGH 8.8 .Net 10.0 — Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privi… 2026-07-14 CVE-2026-47304 HIGH 8.1 Microsoft Visual Studio 2017 Version 15.9 (Includes 15.0 15.8) — Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security … 2026-07-14 CVE-2026-47305 HIGH 7.8 Microsoft Visual Studio 2022 Version 17.12 — Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-47632 HIGH 8.8 Azure Monitor Agent Metrics Extension — Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges o… 2026-07-14 CVE-2026-47642 HIGH 7.8 Microsoft 365 Apps For Enterprise — Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-47967 HIGH 7.8 Audition — Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in … 2026-07-14 CVE-2026-47968 HIGH 7.8 Audition — Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in … 2026-07-14 CVE-2026-47969 MEDIUM 5.5 Audition — Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.… 2026-07-14 CVE-2026-48272 HIGH 7.8 Creative Cloud Desktop — Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in a… 2026-07-14 CVE-2026-48275 HIGH 8.6 Illustrator Desktop 2026 — Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code executio… 2026-07-14 CVE-2026-48287 HIGH 7.4 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary c… 2026-07-14 CVE-2026-48290 HIGH 8.2 Content Credentials Rust Sdk — CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in… 2026-07-14 CVE-2026-48295 HIGH 7.5 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result… 2026-07-14 CVE-2026-48296 MEDIUM 6.2 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could resu… 2026-07-14 CVE-2026-48298 MEDIUM 6.2 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could resu… 2026-07-14 CVE-2026-48302 MEDIUM 6.2 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an appl… 2026-07-14 CVE-2026-48309 HIGH 7.8 Audition — Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in … 2026-07-14 CVE-2026-48311 HIGH 7.8 Adobe Bridge — Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in th… 2026-07-14 CVE-2026-48312 MEDIUM 6.8 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Secur… 2026-07-14 CVE-2026-48334 CRITICAL 9.3 Illustrator Desktop 2026 — Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code exec… 2026-07-14 CVE-2026-48335 HIGH 7.8 Illustrator Desktop 2026 — Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution … 2026-07-14 CVE-2026-48336 HIGH 7.8 Illustrator Desktop 2026 — Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution … 2026-07-14 CVE-2026-48337 HIGH 7.8 Illustrator Desktop 2026 — Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution … 2026-07-14 CVE-2026-48339 HIGH 7.8 Adobe Bridge — Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution… 2026-07-14 CVE-2026-48340 HIGH 7.8 Adobe Bridge — Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execu… 2026-07-14 CVE-2026-48341 HIGH 7.8 Adobe Bridge — Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in th… 2026-07-14 CVE-2026-48342 HIGH 7.8 Adobe Bridge — Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code exec… 2026-07-14 CVE-2026-48343 HIGH 7.8 Adobe Bridge — Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in th… 2026-07-14 CVE-2026-48344 HIGH 7.8 Creative Cloud Desktop — Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that c… 2026-07-14 CVE-2026-48345 HIGH 8.2 Adobe Animate 2023 — Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec… 2026-07-14 CVE-2026-48346 HIGH 7.9 Adobe Animate 2023 — Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in… 2026-07-14 CVE-2026-48347 HIGH 7.7 Adobe Animate 2023 — Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec… 2026-07-14 CVE-2026-48348 HIGH 7.7 Adobe Animate 2023 — Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution … 2026-07-14 CVE-2026-48349 HIGH 8.1 Adobe Animate 2023 — Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution … 2026-07-14 CVE-2026-48350 HIGH 8.6 Adobe Animate 2023 — Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne… 2026-07-14 CVE-2026-48351 HIGH 7.5 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an appl… 2026-07-14 CVE-2026-48352 HIGH 7.5 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an appl… 2026-07-14 CVE-2026-48353 MEDIUM 5.5 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary… 2026-07-14 CVE-2026-48354 MEDIUM 6.2 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an… 2026-07-14 CVE-2026-48357 MEDIUM 6.2 Content Credentials Rust Sdk — CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to a… 2026-07-14 CVE-2026-48365 HIGH 7.8 Audition — Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in … 2026-07-14 CVE-2026-48368 HIGH 7.8 Audition — Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in … 2026-07-14 CVE-2026-48561 CRITICAL 9.6 Microsoft 365 Copilot For Android — Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allow… 2026-07-14 CVE-2026-48564 HIGH 8.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network… 2026-07-14 CVE-2026-48571 HIGH 7 Windows 11 Version 23h2 — Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-48572 HIGH 7 Windows 11 Version 23h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Ins… 2026-07-14 CVE-2026-48580 MEDIUM 5.5 Microsoft 365 Apps For Enterprise — Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose informatio… 2026-07-14 CVE-2026-48581 HIGH 7.8 Microsoft Surface Go — Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privi… 2026-07-14 CVE-2026-49162 HIGH 7 Windows 11 Version 24h2 — Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49164 HIGH 8.1 Windows 10 Version 1607 — Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code… 2026-07-14 CVE-2026-49165 HIGH 7.1 Windows 10 Version 1607 — Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose informa… 2026-07-14 CVE-2026-49166 HIGH 7.8 Windows 11 Version 24h2 — Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49167 MEDIUM 4.7 Windows 10 Version 1809 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49168 MEDIUM 6.8 Windows 10 Version 1607 — Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate pri… 2026-07-14 CVE-2026-49169 HIGH 8 Windows Server 2025 — Use after free in DNS Server allows an authorized attacker to execute code over a network. 2026-07-14 CVE-2026-49170 HIGH 7.8 Windows 10 Version 1809 — Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to ele… 2026-07-14 CVE-2026-49171 HIGH 7.5 Windows 10 Version 1607 — Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49172 CRITICAL 9.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a netwo… 2026-07-14 CVE-2026-49173 HIGH 7.8 Windows 11 Version 26h1 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49174 MEDIUM 6.1 Windows 10 Version 1809 — Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform… 2026-07-14 CVE-2026-49175 HIGH 7.8 Windows 10 Version 21h2 — Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49176 HIGH 7.8 Windows 10 Version 1607 — Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges loc… 2026-07-14 CVE-2026-49177 MEDIUM 5.5 Windows 10 Version 1607 — Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. 2026-07-14 CVE-2026-49178 HIGH 8.8 Windows 10 Version 1607 — Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code o… 2026-07-14 CVE-2026-49180 MEDIUM 5.5 Windows 10 Version 1607 — Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an… 2026-07-14 CVE-2026-49181 HIGH 7.5 Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privi… 2026-07-14 CVE-2026-49183 HIGH 7 Windows 10 Version 1809 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboa… 2026-07-14 CVE-2026-49184 HIGH 8.4 Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-49783 HIGH 7.8 Windows 10 Version 1607 — Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to byp… 2026-07-14 CVE-2026-49784 HIGH 7 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windo… 2026-07-14 CVE-2026-49787 HIGH 7.5 Windows 10 Version 1607 — Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to de… 2026-07-14 CVE-2026-49788 HIGH 7.5 Windows 10 Version 1607 — Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service… 2026-07-14 CVE-2026-49789 HIGH 7.3 Windows 10 Version 1607 — Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49790 HIGH 7.3 Windows 10 Version 1607 — Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 2026-07-14 CVE-2026-49791 HIGH 7.1 Windows 10 Version 1607 — Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (R… 2026-07-14 CVE-2026-49792 HIGH 7.8 Windows 10 Version 1607 — Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code… 2026-07-14 CVE-2026-49793 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute co… 2026-07-14 CVE-2026-49794 MEDIUM 4.6 Windows 10 Version 1607 — Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclos… 2026-07-14 CVE-2026-49795 HIGH 8.8 Windows 10 Version 1809 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49796 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-49797 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-49798 CRITICAL 9.3 Windows 10 Version 1607 — Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49799 MEDIUM 6.5 Windows 10 Version 1607 — Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an auth… 2026-07-14 CVE-2026-49800 HIGH 7.8 Windows 10 Version 1809 — Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attack… 2026-07-14 CVE-2026-49801 MEDIUM 5.5 Windows 10 Version 1607 — Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 2026-07-14 CVE-2026-49802 HIGH 7 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Pri… 2026-07-14 CVE-2026-49803 HIGH 7 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX De… 2026-07-14 CVE-2026-49804 MEDIUM 6.6 Windows 10 Version 1607 — Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges w… 2026-07-14 CVE-2026-49805 HIGH 7 Windows 10 Version 1607 — Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-49806 HIGH 7 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Pri… 2026-07-14 CVE-2026-49807 MEDIUM 6.2 Windows 10 Version 1809 — Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker … 2026-07-14 CVE-2026-49808 HIGH 7.8 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel … 2026-07-14 CVE-2026-50293 HIGH 7.8 Windows 10 Version 21h2 — Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50294 MEDIUM 6.2 Windows 10 Version 1607 — Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unautho… 2026-07-14 CVE-2026-50295 MEDIUM 5.5 Windows 11 Version 24h2 — Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feat… 2026-07-14 CVE-2026-50296 HIGH 7 Windows 10 Version 1607 — Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50297 HIGH 7 Windows 10 Version 1607 — Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50298 MEDIUM 6.8 Windows 10 Version 1607 — Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges … 2026-07-14 CVE-2026-50299 MEDIUM 6.8 Windows 10 Version 1607 — Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute cod… 2026-07-14 CVE-2026-50300 MEDIUM 5.5 Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information… 2026-07-14 CVE-2026-50301 HIGH 7.8 Microsoft 365 Apps For Enterprise — Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-50302 MEDIUM 4.2 Windows 10 Version 21h2 — Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a … 2026-07-14 CVE-2026-50303 MEDIUM 5.5 Windows 10 Version 1809 — Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacke… 2026-07-14 CVE-2026-50304 HIGH 7.5 Microsoft .Net Framework 3.5 — Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny se… 2026-07-14 CVE-2026-50305 HIGH 7.8 Windows 11 Version 24h2 — Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50306 HIGH 7.8 Windows 10 Version 1607 — Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50307 HIGH 7 Windows 10 Version 1809 — Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50308 HIGH 7.8 Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally… 2026-07-14 CVE-2026-50309 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 2026-07-14 CVE-2026-50310 MEDIUM 4.7 Windows 10 Version 1809 — Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose in… 2026-07-14 CVE-2026-50311 HIGH 7.8 Windows 10 Version 1607 — Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50312 MEDIUM 4.7 Windows 10 Version 1607 — Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi… 2026-07-14 CVE-2026-50313 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-50314 HIGH 7.8 Microsoft 365 Apps For Enterprise — Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-50315 HIGH 7.8 Windows 11 Version 24h2 — Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges loca… 2026-07-14 CVE-2026-50316 MEDIUM 5.5 Windows 10 Version 21h2 — Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose i… 2026-07-14 CVE-2026-50317 HIGH 7.8 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operati… 2026-07-14 CVE-2026-50318 HIGH 7.8 Windows 10 Version 1607 — Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate p… 2026-07-14 CVE-2026-50321 HIGH 7.8 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Dri… 2026-07-14 CVE-2026-50322 HIGH 7 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime… 2026-07-14 CVE-2026-50323 HIGH 7 Windows 11 Version 24h2 — Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50324 MEDIUM 5.9 Microsoft .Net Framework 3.5 — Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows … 2026-07-14 CVE-2026-50325 HIGH 7 Windows 10 Version 1607 — Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50326 HIGH 7.8 Windows 10 Version 21h2 — Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50327 HIGH 7.8 Windows 11 Version 24h2 — Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. 2026-07-14 CVE-2026-50328 HIGH 7.5 Windows 10 Version 1607 — Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over … 2026-07-14 CVE-2026-50329 HIGH 7.8 Windows 10 Version 1809 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50330 HIGH 7.5 Windows 10 Version 1607 — Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over… 2026-07-14 CVE-2026-50331 HIGH 7.8 Windows 10 Version 1607 — Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50332 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50333 HIGH 7.8 Windows 10 Version 1607 — Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate… 2026-07-14 CVE-2026-50334 MEDIUM 5.5 Windows 10 Version 1607 — Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attack… 2026-07-14 CVE-2026-50335 HIGH 7.8 Windows 10 Version 1809 — Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges local… 2026-07-14 CVE-2026-50336 HIGH 7.8 Windows 11 Version 24h2 — Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50337 HIGH 7.8 Windows 10 Version 1607 — Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges … 2026-07-14 CVE-2026-50338 HIGH 8.2 Azure Spring Apps — Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a networ… 2026-07-14 CVE-2026-50339 MEDIUM 5.5 Windows 10 Version 1809 — Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized … 2026-07-14 CVE-2026-50340 HIGH 8.5 Windows 11 Version 24h2 — Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. 2026-07-14 CVE-2026-50341 MEDIUM 5.5 Windows 10 Version 1607 — Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. 2026-07-14 CVE-2026-50342 HIGH 8.8 Windows 11 Version 24h2 — Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges loc… 2026-07-14 CVE-2026-50343 HIGH 7.8 Windows 10 Version 1809 — Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges… 2026-07-14 CVE-2026-50344 HIGH 7.8 Windows 10 Version 1607 — Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50345 HIGH 7 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime… 2026-07-14 CVE-2026-50346 HIGH 7.8 Windows 10 Version 1607 — Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50347 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-50348 HIGH 7 Windows 10 Version 1809 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime… 2026-07-14 CVE-2026-50350 MEDIUM 5.5 Windows 10 Version 21h2 — Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows … 2026-07-14 CVE-2026-50351 HIGH 7.8 Windows 10 Version 1607 — Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate pr… 2026-07-14 CVE-2026-50352 MEDIUM 5.5 Windows 10 Version 1607 — Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authori… 2026-07-14 CVE-2026-50353 HIGH 7.8 Windows 11 Version 24h2 — Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50354 HIGH 7.1 Windows 10 Version 1607 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50355 HIGH 7.5 Microsoft .Net Framework 3.5 — Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny se… 2026-07-14 CVE-2026-50356 HIGH 7 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windo… 2026-07-14 CVE-2026-50357 HIGH 7.8 Windows 10 Version 1607 — Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code… 2026-07-14 CVE-2026-50358 HIGH 7 Windows 10 Version 1607 — Use after free in Windows Media allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50359 HIGH 7 Windows 10 Version 1607 — Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50360 HIGH 8.8 Windows 10 Version 21h2 — Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to el… 2026-07-14 CVE-2026-50361 HIGH 7.8 Windows 11 Version 24h2 — Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50362 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute … 2026-07-14 CVE-2026-50363 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges l… 2026-07-14 CVE-2026-50364 HIGH 7.3 Windows 10 Version 21h2 — Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized a… 2026-07-14 CVE-2026-50365 HIGH 8 Windows 10 Version 1607 — Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjac… 2026-07-14 CVE-2026-50366 MEDIUM 6.5 Windows 10 Version 1607 — Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service ove… 2026-07-14 CVE-2026-50367 HIGH 7.8 Windows 10 Version 1809 — Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized att… 2026-07-14 CVE-2026-50368 HIGH 7.5 Microsoft .Net Framework 3.5 — Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny se… 2026-07-14 CVE-2026-50369 HIGH 8.8 Windows 10 Version 1607 — Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a n… 2026-07-14 CVE-2026-50370 HIGH 8.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adja… 2026-07-14 CVE-2026-50371 HIGH 7 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV a… 2026-07-14 CVE-2026-50372 HIGH 7 Windows 10 Version 1607 — Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges loc… 2026-07-14 CVE-2026-50373 HIGH 7.8 Windows 10 Version 1809 — Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privile… 2026-07-14 CVE-2026-50374 MEDIUM 6.3 Windows 10 Version 1809 — Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges w… 2026-07-14 CVE-2026-50375 MEDIUM 6.3 Windows 10 Version 1809 — Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50376 MEDIUM 6.5 Windows 10 Version 1607 — Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a ne… 2026-07-14 CVE-2026-50377 MEDIUM 5.5 Windows 10 Version 1607 — Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50378 HIGH 7.8 Windows 10 Version 1809 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Gua… 2026-07-14 CVE-2026-50379 HIGH 7.5 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media a… 2026-07-14 CVE-2026-50380 CRITICAL 9.6 Windows 10 Version 1607 — Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. 2026-07-14 CVE-2026-50381 MEDIUM 5.5 Windows 10 Version 21h2 — Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an … 2026-07-14 CVE-2026-50382 HIGH 8.8 Windows 10 Version 1809 — Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. 2026-07-14 CVE-2026-50383 MEDIUM 6.1 Windows 10 Version 1809 — Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information loc… 2026-07-14 CVE-2026-50384 HIGH 7 Windows 10 Version 1809 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Se… 2026-07-14 CVE-2026-50385 HIGH 8.8 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime… 2026-07-14 CVE-2026-50386 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-50387 HIGH 7.8 Microsoft Office 365 For Mac — Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50388 HIGH 7.8 Windows 10 Version 1607 — Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. 2026-07-14 CVE-2026-50389 MEDIUM 5.5 Windows 10 Version 1607 — Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attac… 2026-07-14 CVE-2026-50390 HIGH 7 Windows 10 Version 1607 — Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker … 2026-07-14 CVE-2026-50391 HIGH 7.8 Windows 10 Version 1607 — Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges loca… 2026-07-14 CVE-2026-50392 HIGH 7 Windows 11 Version 24h2 — Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50393 HIGH 7 Windows 11 Version 24h2 — Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50394 MEDIUM 5.5 Windows 10 Version 1607 — Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to d… 2026-07-14 CVE-2026-50396 HIGH 7 Windows 11 Version 24h2 — Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50397 HIGH 7 Windows 10 Version 1607 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50398 HIGH 8.8 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media a… 2026-07-14 CVE-2026-50399 HIGH 7.8 Windows 10 Version 21h2 — Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50400 HIGH 7.8 Windows 10 Version 1607 — Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges local… 2026-07-14 CVE-2026-50401 MEDIUM 5.5 Windows 10 Version 1809 — Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose informa… 2026-07-14 CVE-2026-50402 HIGH 7.8 Windows 10 Version 1607 — Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges… 2026-07-14 CVE-2026-50403 HIGH 7 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime… 2026-07-14 CVE-2026-50404 HIGH 7 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media a… 2026-07-14 CVE-2026-50405 HIGH 7.8 Windows 10 Version 1607 — Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker t… 2026-07-14 CVE-2026-50406 HIGH 7 Windows 10 Version 21h2 — Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50407 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate pr… 2026-07-14 CVE-2026-50408 MEDIUM 5.5 Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 2026-07-14 CVE-2026-50409 MEDIUM 5.5 Windows 10 Version 1607 — Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized atta… 2026-07-14 CVE-2026-50410 HIGH 7 Windows 10 Version 1809 — Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50411 HIGH 7.5 Microsoft .Net Framework 3.5 — Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to… 2026-07-14 CVE-2026-50412 HIGH 7.8 Windows 10 Version 1607 — Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50413 HIGH 8.8 Windows 11 Version 24h2 — Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50414 HIGH 7.5 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media a… 2026-07-14 CVE-2026-50415 MEDIUM 5.3 Windows 10 Version 1809 — Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to… 2026-07-14 CVE-2026-50416 LOW 3.3 Windows 11 Version 24h2 — Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to … 2026-07-14 CVE-2026-50417 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 2026-07-14 CVE-2026-50418 MEDIUM 5.1 Windows 11 Version 24h2 — Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally… 2026-07-14 CVE-2026-50419 LOW 3.3 Windows 10 Version 1607 — Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to … 2026-07-14 CVE-2026-50420 MEDIUM 6.2 Windows 11 Version 24h2 — Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally. 2026-07-14 CVE-2026-50421 HIGH 7.8 Windows 10 Version 1607 — Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Teleme… 2026-07-14 CVE-2026-50422 HIGH 7.8 Windows 10 Version 1607 — Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50423 HIGH 7.8 Windows 10 Version 21h2 — Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50424 HIGH 7.5 Windows 11 Version 24h2 — Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service ove… 2026-07-14 CVE-2026-50425 HIGH 7.8 Windows 10 Version 21h2 — Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges loc… 2026-07-14 CVE-2026-50426 MEDIUM 6.8 Windows 10 Version 1607 — Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. 2026-07-14 CVE-2026-50427 HIGH 7.8 Windows 10 Version 1809 — Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50428 HIGH 7.1 Windows 11 Version 26h1 — Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker… 2026-07-14 CVE-2026-50429 HIGH 8.2 Windows 10 Version 1607 — Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. 2026-07-14 CVE-2026-50430 MEDIUM 5.5 Windows 10 Version 1607 — Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized … 2026-07-14 CVE-2026-50431 MEDIUM 5.5 Windows 10 Version 1607 — Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability 2026-07-14 CVE-2026-50432 MEDIUM 5.3 Windows 10 Version 1607 — Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over … 2026-07-14 CVE-2026-50433 HIGH 7.8 Windows 10 Version 1607 — Use after free in Windows Media allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50434 MEDIUM 5.5 Windows 10 Version 21h2 — Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized … 2026-07-14 CVE-2026-50435 HIGH 7.8 Windows 10 Version 1607 — Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50436 HIGH 7.8 Windows 11 Version 24h2 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-07-14 CVE-2026-50437 MEDIUM 5.5 Windows 10 Version 1607 — Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 2026-07-14