← Browse

Microsoft

300 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-62906 HIGH 7.4 Microsoft Discovery Studio — Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauth… 2026-09-03 CVE-2026-62916 CRITICAL 9.1 Microsoft Entra — Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker… 2026-09-03 CVE-2026-65818 HIGH 8.5 Microsoft Power Platform — Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over … 2026-09-03 CVE-2026-69857 HIGH 8.5 Azure Cosmos Db — Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform s… 2026-09-03 CVE-2026-70178 HIGH 8.5 Microsoft Fabric — Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. 2026-09-03 CVE-2026-70352 CRITICAL 10 Azure Ai Language Authoring — Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate p… 2026-09-03 CVE-2026-80098 CRITICAL 9.3 Microsoft Copilot Studio — Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate … 2026-09-03 CVE-2026-83711 CRITICAL 10 Entra — Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorize… 2026-09-03 CVE-2026-84452 HIGH 8.6 Winml Cli — Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Window…● PoC 2026-09-02 CVE-2026-84329 MEDIUM 5.3 Chrome — Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote a… 2026-09-01 CVE-2026-84334 HIGH 8.1 Chrome — Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local at… 2026-09-01 CVE-2026-84351 HIGH 8.3 Chrome — Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had… 2026-09-01 CVE-2026-58616 MEDIUM 4.4 Microsoft Edge (Chromium Based) — Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (M… 2026-08-28 CVE-2026-62904 MEDIUM 5.4 Microsoft Edge (Chromium Based) — Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose informa… 2026-08-28 CVE-2026-66323 MEDIUM 5.4 Microsoft Edge (Chromium Based) — Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthor… 2026-08-28 CVE-2026-66324 MEDIUM 6.5 Microsoft Edge (Chromium Based) — External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to pe… 2026-08-28 CVE-2026-66798 MEDIUM 4.3 Microsoft Edge (Chromium Based) — Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netwo… 2026-08-28 CVE-2026-70309 MEDIUM 5.4 Microsoft Edge (Chromium Based) — Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a securit… 2026-08-28 CVE-2026-70331 MEDIUM 5.4 Microsoft Edge (Chromium Based) — Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attac… 2026-08-28 CVE-2026-72984 HIGH 8.8 Microsoft Edge (Chromium Based) — Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an una… 2026-08-28 CVE-2026-12878 HIGH 8.6 Codefresh — In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to… 2026-08-25 CVE-2026-76193 CRITICAL 10 Adobe Campaign Classic — Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could resu… 2026-08-25 CVE-2026-76195 CRITICAL 10 Adobe Campaign Classic — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Comma… 2026-08-25 CVE-2026-76197 CRITICAL 10 Adobe Campaign Classic — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Comma… 2026-08-25 CVE-2026-78892 HIGH 7.1 Chrome — Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local at… 2026-08-25 CVE-2026-78915 HIGH 7.5 Chrome — Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacke… 2026-08-25 CVE-2026-78952 HIGH 8.3 Chrome — Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacke… 2026-08-25 CVE-2026-78978 HIGH 8.8 Chrome — Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to… 2026-08-25 CVE-2026-78979 MEDIUM 4.3 Chrome — Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leverag… 2026-08-25 CVE-2026-78989 CRITICAL 9.6 Chrome — Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to… 2026-08-25 CVE-2026-79019 CRITICAL 9.6 Chrome — Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker t… 2026-08-25 CVE-2026-79048 HIGH 8.8 Chrome — Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker t… 2026-08-25 CVE-2026-79084 MEDIUM 4.3 Chrome — Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed … 2026-08-25 CVE-2026-79123 MEDIUM 6.5 Chrome — Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote… 2026-08-25 CVE-2026-79126 MEDIUM 5.9 Chrome — Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 … 2026-08-25 CVE-2026-79138 CRITICAL 9.6 Chrome — Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker t… 2026-08-25 CVE-2026-79139 HIGH 7.5 Chrome — Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote atta… 2026-08-25 CVE-2026-79175 HIGH 8.3 Chrome — Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacke… 2026-08-25 CVE-2026-79177 MEDIUM 6.5 Chrome — Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attack… 2026-08-25 CVE-2026-79194 HIGH 8.1 Chrome — Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker t… 2026-08-25 CVE-2026-79240 HIGH 8.8 Chrome — Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker t… 2026-08-25 CVE-2026-79243 MEDIUM 6.5 Chrome — Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remot… 2026-08-25 CVE-2026-79247 HIGH 8.3 Chrome — Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker w… 2026-08-25 CVE-2026-79253 MEDIUM 6.5 Chrome — Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote at… 2026-08-25 CVE-2026-79285 MEDIUM 6.5 Chrome — Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacke… 2026-08-25 CVE-2026-62316 HIGH 8.8 Ufo — Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, u…● PoC 2026-08-21 CVE-2026-69502 CRITICAL 10 Azure Sql Database — Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges… 2026-08-21 CVE-2026-55013 HIGH 7.1 Windows Remote Help — Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoof… 2026-08-20 CVE-2026-55015 MEDIUM 5.5 Windows Remote Help — Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. 2026-08-20 CVE-2026-62834 CRITICAL 9.3 Azure Data Factory — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elev… 2026-08-20 CVE-2026-63509 CRITICAL 9.9 Microsoft Fabric — Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network… 2026-08-20 CVE-2026-65770 CRITICAL 10 Azure Managed Instance For Apache Cassandra — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance f… 2026-08-20 CVE-2026-65801 CRITICAL 10 Microsoft Exchange Online — Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate pri… 2026-08-20 CVE-2026-65816 CRITICAL 10 Azure Web Apps — Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileg… 2026-08-20 CVE-2026-66309 CRITICAL 9.1 Azure Sql Database — Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a netwo… 2026-08-20 CVE-2026-66800 HIGH 8.6 Azure Data Factory — Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose informati… 2026-08-20 CVE-2026-68782 CRITICAL 9.9 Azure Sql Database — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database all… 2026-08-20 CVE-2026-68789 CRITICAL 9.9 Azure Sql Database — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database all… 2026-08-20 CVE-2026-69400 CRITICAL 9.6 Azure Logic Apps — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an u… 2026-08-20 CVE-2026-69419 HIGH 8.5 Azure Data Manager For Energy — Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code … 2026-08-20 CVE-2026-69519 HIGH 8.6 Azure Stack Hci — Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information ove… 2026-08-20 CVE-2026-69543 HIGH 8.5 Azure Virtual Machines — Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileg… 2026-08-20 CVE-2026-69555 CRITICAL 10 Azure Arc — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 2026-08-20 CVE-2026-69558 HIGH 8.6 Microsoft Partner Center — Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker t… 2026-08-20 CVE-2026-69836 CRITICAL 10 Microsoft Entra — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a… 2026-08-20 CVE-2026-69851 CRITICAL 9.9 Microsoft Entra — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg… 2026-08-20 CVE-2026-69855 HIGH 7.7 Microsoft Copilot In Azure — Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose inf… 2026-08-20 CVE-2026-70105 MEDIUM 6.5 Microsoft 365 Apps For Enterprise — Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information ove… 2026-08-20 CVE-2026-19875 HIGH 7.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email informati… 2026-08-19 CVE-2026-62727 HIGH 7 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho… 2026-08-19 CVE-2026-69550 MEDIUM 6.5 Windows App For Mac — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a net… 2026-08-19 CVE-2026-76259 HIGH 8.8 Splunk Enterprise — In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with … 2026-08-19 CVE-2026-24301 HIGH 8.8 Copilot Web — Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allow… 2026-08-18 CVE-2026-76037 HIGH 8.4 Chrome — Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local at… 2026-08-18 CVE-2026-73851 MEDIUM 6.1 Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or … 2026-08-17 CVE-2026-50523 HIGH 7.8 Powershell 7.4 — Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell al… 2026-08-14 CVE-2026-69414 HIGH 7.8 Microsoft Malware Protection Engine — Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defend…● PoC 2026-08-14 CVE-2026-72970 HIGH 8.3 Microsoft Edge (Chromium Based) — Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code … 2026-08-14 CVE-2026-10571 MEDIUM 5.7 Websphere Application Server Liberty — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused… 2026-08-13 CVE-2026-14525 CRITICAL 9.4 Websphere Application Server Liberty — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty … 2026-08-13 CVE-2026-19297 CRITICAL 9.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accou… 2026-08-13 CVE-2026-19696 MEDIUM 6.6 Wireshark — Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Wi…● PoC 2026-08-13 CVE-2026-73296 CRITICAL 9.4 Ufo — Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, c…● PoC 2026-08-12 CVE-2026-73297 MEDIUM 6.9 Ufo — Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _…● PoC 2026-08-12 CVE-2026-73298 HIGH 8.7 Container Migration Solution Accelerator — The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-ag… 2026-08-12 CVE-2026-73299 CRITICAL 10 Prompty — Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript … 2026-08-12 CVE-2026-40375 MEDIUM 6.5 Microsoft Dynamics 365 Business Central 2024 Release Wave 2 — Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over … 2026-08-11 CVE-2026-42976 HIGH 7.8 Windows 10 Version 1607 — Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privi… 2026-08-11 CVE-2026-47285 MEDIUM 6.5 Visual Studio Code — Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allo… 2026-08-11 CVE-2026-47299 HIGH 7.2 Azure Monitor Agent Linux Extension — Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent all… 2026-08-11 CVE-2026-47940 HIGH 7.8 Lightroom Classic — Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrar… 2026-08-11 CVE-2026-48397 HIGH 8.6 Lightroom Classic — Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitr… 2026-08-11 CVE-2026-48404 HIGH 7.8 Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec… 2026-08-11 CVE-2026-48405 HIGH 7.8 Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec… 2026-08-11 CVE-2026-48406 HIGH 7.8 Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec… 2026-08-11 CVE-2026-48407 HIGH 7.8 Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec… 2026-08-11 CVE-2026-48408 HIGH 7.8 Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec… 2026-08-11 CVE-2026-48409 HIGH 7.8 Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec… 2026-08-11 CVE-2026-48410 HIGH 7.8 Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec… 2026-08-11 CVE-2026-48441 HIGH 8.6 Lightroom Classic — Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Travers… 2026-08-11 CVE-2026-48447 HIGH 7.7 Lightroom Classic — Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code … 2026-08-11 CVE-2026-49179 HIGH 8.8 Windows 10 Version 1607 — Improper neutralization of special elements used in a command ('command injection') in Windows Active Director… 2026-08-11 CVE-2026-50472 HIGH 7 Windows 10 Version 1607 — Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-50516 CRITICAL 9.4 Azure Kubernetes Service — Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized atta… 2026-08-11 CVE-2026-54113 HIGH 7.5 Windows 10 Version 1607 — Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny… 2026-08-11 CVE-2026-54123 MEDIUM 5.5 Microsoft Defender For Endpoint For Mac — Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an author… 2026-08-11 CVE-2026-54981 HIGH 7.8 Python Extension For Visual Studio Code — Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an un… 2026-08-11 CVE-2026-54984 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locall… 2026-08-11 CVE-2026-56174 HIGH 7.8 Windows 10 Version 1809 — Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-56179 HIGH 8.3 Windows 11 Version 24h2 — Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perfor… 2026-08-11 CVE-2026-57104 HIGH 8.8 Azure Storage Explorer — Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer… 2026-08-11 CVE-2026-57105 HIGH 8 Microsoft Sharepoint Server 2019 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share… 2026-08-11 CVE-2026-58612 HIGH 7.4 Powershell 7.4 — Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose in… 2026-08-11 CVE-2026-58639 MEDIUM 6.5 Microsoft Sharepoint Enterprise Server 2016 — Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spo… 2026-08-11 CVE-2026-58641 HIGH 7.8 Skiasharp — Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-58650 HIGH 7.8 Visual Studio Code — Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypa… 2026-08-11 CVE-2026-58651 HIGH 7.8 Microsoft 365 Apps For Enterprise — Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 2026-08-11 CVE-2026-59113 HIGH 8.8 Visual Studio Code — Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. 2026-08-11 CVE-2026-59119 HIGH 7.3 Powershell 7.4 — Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges loca… 2026-08-11 CVE-2026-59122 HIGH 7 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho… 2026-08-11 CVE-2026-59124 CRITICAL 9.8 Microsoft Hpc Pack 2019 — Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized at… 2026-08-11 CVE-2026-59125 HIGH 7 Windows 10 Version 1607 — Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges … 2026-08-11 CVE-2026-59126 HIGH 7 Windows 10 Version 21h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event L… 2026-08-11 CVE-2026-59127 HIGH 7.8 Windows 10 Version 1607 — Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locall… 2026-08-11 CVE-2026-59128 MEDIUM 5.5 Windows 10 Version 1607 — Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose informati… 2026-08-11 CVE-2026-59130 MEDIUM 5.6 Windows 10 Version 1607 — No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-59131 MEDIUM 5.6 Windows 10 Version 1607 — No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-59132 HIGH 7.5 Windows 10 Version 1607 — Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. 2026-08-11 CVE-2026-59133 HIGH 8.8 Microsoft Hpc Pack 2019 — Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized … 2026-08-11 CVE-2026-59134 HIGH 7.5 Windows 10 Version 1607 — Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a net… 2026-08-11 CVE-2026-59135 MEDIUM 5.5 Windows 10 Version 1607 — Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose informatio… 2026-08-11 CVE-2026-59136 MEDIUM 5.5 Windows 10 Version 1607 — Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose informati… 2026-08-11 CVE-2026-59137 MEDIUM 5.5 Windows 10 Version 1607 — Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose infor… 2026-08-11 CVE-2026-59138 MEDIUM 6.5 Windows 10 Version 1607 — Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service ov… 2026-08-11 CVE-2026-61345 MEDIUM 6.5 Windows 10 Version 1607 — Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service ov… 2026-08-11 CVE-2026-61346 HIGH 7 Windows 10 Version 1809 — Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61347 MEDIUM 5.5 Windows 10 Version 1607 — Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locall… 2026-08-11 CVE-2026-61348 HIGH 7 Windows 10 Version 1607 — Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi… 2026-08-11 CVE-2026-61349 HIGH 7.8 Windows 10 Version 1607 — Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61350 MEDIUM 4.6 Windows 10 Version 1607 — Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attac… 2026-08-11 CVE-2026-61352 HIGH 7.5 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop … 2026-08-11 CVE-2026-61353 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges lo… 2026-08-11 CVE-2026-61355 HIGH 7.8 Windows 10 Version 21h2 — Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges … 2026-08-11 CVE-2026-61356 HIGH 7.8 Windows 10 Version 1809 — Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker … 2026-08-11 CVE-2026-61357 HIGH 7.8 Windows 11 Version 24h2 — Use after free in Application Information Services allows an authorized attacker to elevate privileges locally… 2026-08-11 CVE-2026-61358 HIGH 7.8 Windows 10 Version 1809 — Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBrok… 2026-08-11 CVE-2026-61359 HIGH 7.8 Windows 11 Version 23h2 — Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61360 MEDIUM 5.5 Windows 10 Version 1607 — Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-61361 HIGH 7 Windows 11 Version 24h2 — Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. 2026-08-11 CVE-2026-61363 HIGH 7.5 Windows 10 Version 1607 — Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a net… 2026-08-11 CVE-2026-61364 HIGH 7.8 Windows 10 Version 1607 — Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker … 2026-08-11 CVE-2026-61365 HIGH 7.8 Windows 10 Version 1607 — Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker … 2026-08-11 CVE-2026-61366 HIGH 7 Windows 10 Version 1607 — Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61367 HIGH 7.8 Windows 10 Version 1607 — Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker … 2026-08-11 CVE-2026-61368 MEDIUM 5 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-61918 MEDIUM 6.5 Windows 10 Version 1607 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a net… 2026-08-11 CVE-2026-61920 MEDIUM 6.6 Windows Server 2012 R2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS all… 2026-08-11 CVE-2026-61921 MEDIUM 6.5 Windows 10 Version 1607 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a net… 2026-08-11 CVE-2026-61923 HIGH 7.8 Windows 10 Version 1809 — Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate pri… 2026-08-11 CVE-2026-61924 MEDIUM 6.5 Windows 10 Version 1607 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a net… 2026-08-11 CVE-2026-61925 HIGH 7.8 Windows 10 Version 1607 — Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61926 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61927 HIGH 7 Windows 11 Version 24h2 — Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61928 MEDIUM 5.5 Windows 10 Version 1607 — Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering… 2026-08-11 CVE-2026-61929 HIGH 7 Windows 11 Version 23h2 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61930 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61932 HIGH 7.8 Windows 10 Version 1607 — Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized… 2026-08-11 CVE-2026-61933 MEDIUM 5.5 Windows 11 Version 24h2 — Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-61934 HIGH 7.8 Windows 11 Version 23h2 — Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61936 MEDIUM 5.5 Windows 10 Version 1809 — Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security … 2026-08-11 CVE-2026-61937 HIGH 7.8 Windows 10 Version 1607 — Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally… 2026-08-11 CVE-2026-61938 HIGH 7 Windows 11 Version 24h2 — Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-61939 HIGH 7 Windows 10 Version 1607 — Use after free in Winlogon allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62688 HIGH 7.8 Windows 11 Version 24h2 — Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges … 2026-08-11 CVE-2026-62690 HIGH 7 Windows 10 Version 1809 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push No… 2026-08-11 CVE-2026-62692 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privile… 2026-08-11 CVE-2026-62693 HIGH 7 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Se… 2026-08-11 CVE-2026-62695 HIGH 7.8 Windows 11 Version 23h2 — Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62696 HIGH 7.8 Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized… 2026-08-11 CVE-2026-62698 HIGH 7.8 Windows 10 Version 1607 — Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privilege… 2026-08-11 CVE-2026-62699 MEDIUM 6.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized a… 2026-08-11 CVE-2026-62700 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62701 HIGH 7.8 Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62702 MEDIUM 6.8 Windows 10 Version 21h2 — Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a net… 2026-08-11 CVE-2026-62703 MEDIUM 5.5 Windows 10 Version 1809 — Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-62705 HIGH 7 Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Fi… 2026-08-11 CVE-2026-62707 HIGH 7.8 Windows 10 Version 1607 — Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges l… 2026-08-11 CVE-2026-62708 MEDIUM 6.4 Windows 11 Version 24h2 — Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. 2026-08-11 CVE-2026-62709 MEDIUM 5.5 Windows 10 Version 1607 — Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-62710 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate priv… 2026-08-11 CVE-2026-62711 HIGH 7.8 Windows 10 Version 1607 — Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62712 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62713 HIGH 7.8 Windows 10 Version 1809 — Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate … 2026-08-11 CVE-2026-62714 MEDIUM 6.5 Windows Server 2012 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info… 2026-08-11 CVE-2026-62715 MEDIUM 6.5 Windows Server 2012 R2 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info… 2026-08-11 CVE-2026-62716 MEDIUM 6.5 Windows Server 2012 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info… 2026-08-11 CVE-2026-62717 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges loca… 2026-08-11 CVE-2026-62718 MEDIUM 6.5 Windows Server 2012 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info… 2026-08-11 CVE-2026-62719 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges loca… 2026-08-11 CVE-2026-62720 MEDIUM 6.5 Windows Server 2012 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info… 2026-08-11 CVE-2026-62721 HIGH 7.8 Windows 10 Version 1607 — Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to … 2026-08-11 CVE-2026-62722 HIGH 7.8 Windows 11 Version 24h2 — Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privilege… 2026-08-11 CVE-2026-62723 HIGH 7 Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62724 HIGH 7 Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62725 HIGH 7 Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62726 HIGH 7 Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62728 HIGH 7 Windows 10 Version 1607 — Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorize… 2026-08-11 CVE-2026-62729 HIGH 7 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho… 2026-08-11 CVE-2026-62730 MEDIUM 5.5 Windows 10 Version 1607 — Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information loc… 2026-08-11 CVE-2026-62732 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges lo… 2026-08-11 CVE-2026-62733 HIGH 7.8 Windows 10 Version 1607 — Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62734 HIGH 7 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho… 2026-08-11 CVE-2026-62735 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62736 HIGH 7.8 Windows 11 Version 23h2 — Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62737 HIGH 7.8 Windows 11 Version 24h2 — Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62738 MEDIUM 5.5 Windows 10 Version 1607 — Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information… 2026-08-11 CVE-2026-62739 HIGH 7.8 Windows 10 Version 1809 — Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62740 MEDIUM 5.5 Windows 10 Version 1607 — Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose informati… 2026-08-11 CVE-2026-62741 HIGH 7.8 Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges… 2026-08-11 CVE-2026-62742 MEDIUM 6.5 Windows Server 2012 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info… 2026-08-11 CVE-2026-62743 MEDIUM 5.5 Windows 10 Version 1607 — Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-62745 MEDIUM 6.5 Windows Server 2012 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info… 2026-08-11 CVE-2026-62746 MEDIUM 5.5 Windows 10 Version 1607 — Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-62747 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate priv… 2026-08-11 CVE-2026-62748 HIGH 7 Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho… 2026-08-11 CVE-2026-62749 HIGH 7 Windows 11 Version 24h2 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62750 MEDIUM 6.5 Windows 10 Version 1607 — Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering … 2026-08-11 CVE-2026-62751 HIGH 7.8 Windows 10 Version 21h2 — Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privi… 2026-08-11 CVE-2026-62752 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62753 HIGH 7 Windows 10 Version 1607 — Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62754 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62755 HIGH 7.8 Windows 10 Version 1607 — Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally… 2026-08-11 CVE-2026-62757 MEDIUM 5.3 Windows 10 Version 1607 — Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass… 2026-08-11 CVE-2026-62758 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevat… 2026-08-11 CVE-2026-62761 HIGH 7.8 Windows Server 2012 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att… 2026-08-11 CVE-2026-62766 HIGH 7 Windows 11 Version 24h2 — Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62768 HIGH 7.8 Windows 10 Version 1607 — Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62769 MEDIUM 6.7 Windows 10 Version 1607 — Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62770 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62771 HIGH 7.8 Windows 10 Version 1809 — Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate … 2026-08-11 CVE-2026-62772 HIGH 7.8 Windows 11 Version 26h1 — Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized … 2026-08-11 CVE-2026-62773 HIGH 7 Windows 10 Version 1607 — Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62774 HIGH 7 Windows 10 Version 1607 — Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62775 MEDIUM 5.5 Windows 11 Version 26h1 — Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att… 2026-08-11 CVE-2026-62776 HIGH 7.8 Windows Server 2012 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att… 2026-08-11 CVE-2026-62777 HIGH 7.8 Windows 10 Version 1607 — Missing authentication for critical function in Windows License Manager allows an authorized attacker to eleva… 2026-08-11 CVE-2026-62778 HIGH 8.1 Windows 10 Version 1607 — Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. 2026-08-11 CVE-2026-62779 HIGH 7.8 Windows 11 Version 24h2 — Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62780 HIGH 7 Windows 11 Version 23h2 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62781 HIGH 8.1 Windows 10 Version 1607 — Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. 2026-08-11 CVE-2026-62782 MEDIUM 6.5 Windows 10 Version 1607 — Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a networ… 2026-08-11 CVE-2026-62783 HIGH 7.8 Windows 10 Version 1809 — Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevat… 2026-08-11 CVE-2026-62784 HIGH 8.8 Windows 10 Version 1607 — Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker… 2026-08-11 CVE-2026-62785 HIGH 8.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized atta… 2026-08-11 CVE-2026-62786 MEDIUM 5.5 Windows 10 Version 1607 — Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-62787 HIGH 7.5 Windows Server 2012 — Use after free in Windows DNS allows an authorized attacker to execute code over a network. 2026-08-11 CVE-2026-62788 HIGH 7 Windows 11 Version 23h2 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62790 HIGH 8.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. 2026-08-11 CVE-2026-62792 HIGH 8.1 Windows 10 Version 1607 — Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 2026-08-11 CVE-2026-62793 MEDIUM 5.5 Windows 10 Version 1607 — Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-62795 HIGH 8.8 Windows 10 Version 1607 — Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to exec… 2026-08-11 CVE-2026-62796 MEDIUM 5.5 Windows 10 Version 1607 — Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-62797 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62798 MEDIUM 5.5 Windows 11 Version 23h2 — Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-62799 HIGH 7.8 Windows 11 Version 26h1 — Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62800 HIGH 8.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. 2026-08-11 CVE-2026-62803 HIGH 7.8 Windows Server 2012 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att… 2026-08-11 CVE-2026-62807 HIGH 7.8 Windows Server 2012 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att… 2026-08-11 CVE-2026-62811 HIGH 7.8 Windows 11 Version 23h2 — Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62812 HIGH 7.8 Windows Server 2012 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att… 2026-08-11 CVE-2026-62814 MEDIUM 6.5 Windows Server 2012 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info… 2026-08-11 CVE-2026-62815 CRITICAL 9.8 Windows 11 Version 23h2 — Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. 2026-08-11 CVE-2026-62816 HIGH 8.8 Windows 10 Version 1607 — Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to … 2026-08-11 CVE-2026-62817 HIGH 8.8 Windows Server 2019 — Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. 2026-08-11 CVE-2026-62818 HIGH 8.8 Windows 10 Version 1607 — Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code … 2026-08-11 CVE-2026-62819 HIGH 8.1 Windows 10 Version 1607 — Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthori… 2026-08-11 CVE-2026-62820 HIGH 8.1 Windows Server 2016 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS all… 2026-08-11 CVE-2026-62822 HIGH 8.8 Windows 10 Version 1607 — Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. 2026-08-11 CVE-2026-62823 HIGH 8.8 Windows Server 2012 — Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adja… 2026-08-11 CVE-2026-62824 HIGH 8.8 Windows 10 Version 1607 — Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a ne… 2026-08-11 CVE-2026-62827 HIGH 8.8 Microsoft Sharepoint Enterprise Server 2016 — Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove… 2026-08-11 CVE-2026-62829 MEDIUM 4.6 Microsoft Sharepoint Server 2019 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share… 2026-08-11 CVE-2026-62832 HIGH 7.8 Windows 10 Version 21h2 — Improper link resolution before file access ('link following') in Windows User Profile Service allows an autho… 2026-08-11 CVE-2026-62837 MEDIUM 6.5 Microsoft Sharepoint Enterprise Server 2016 — Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information o… 2026-08-11 CVE-2026-62839 MEDIUM 6.5 Microsoft Sharepoint Enterprise Server 2016 — Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform s… 2026-08-11 CVE-2026-62842 MEDIUM 5.5 Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 2026-08-11 CVE-2026-62869 HIGH 8.8 Microsoft Entra — Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoo… 2026-08-11 CVE-2026-62871 HIGH 7.8 .Net 8.0 — Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. 2026-08-11 CVE-2026-62872 HIGH 8.8 Microsoft .Net Framework 3.5 — Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. 2026-08-11 CVE-2026-62876 HIGH 7.8 Windows 10 Version 1607 — Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62877 HIGH 7.8 Windows 10 Version 1607 — Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62878 CRITICAL 9.8 Windows Server 2012 — Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. 2026-08-11 CVE-2026-62880 HIGH 7.8 Windows 10 Version 1607 — Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62881 MEDIUM 6.7 Windows 10 Version 1607 — Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62882 MEDIUM 4.3 Microsoft 365 Apps For Enterprise — Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform sp… 2026-08-11 CVE-2026-62883 MEDIUM 6.7 Windows 10 Version 1607 — Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62885 HIGH 7.8 Windows 10 Version 1607 — Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62886 HIGH 7.8 .Net 10.0 — Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. 2026-08-11 CVE-2026-62887 MEDIUM 5.5 Windows 10 Version 1607 — Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. 2026-08-11 CVE-2026-62888 HIGH 7.8 Windows 10 Version 21h2 — Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 2026-08-11