SB2026090906 - Multiple vulnerabilities in Microsoft Windows
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 712 vulnerabilities.
1) Race condition (CVE-ID: CVE-2026-50349)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to concurrent execution using a shared resource with improper synchronization (race condition) in the Windows Ancillary Function Driver for WinSock when concurrently accessing a shared resource. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
2) Use-after-free (CVE-ID: CVE-2026-56172)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows VHD miniport driver when accessed locally. A local user can exploit the use-after-free to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
3) Use-after-free (CVE-ID: CVE-2026-56177)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Server when it is accessed locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
4) Out-of-bounds read (CVE-ID: CVE-2026-56198)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Microsoft Trace Data Helper when it is used locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
5) Use-after-free (CVE-ID: CVE-2026-62694)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Installer when winning a race condition. A local user can exploit the use-after-free condition to elevate privileges.
6) Use-after-free (CVE-ID: CVE-2026-62697)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Push Notifications when processing notifications locally. A local user can exploit the use-after-free to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
7) Out-of-bounds read (CVE-ID: CVE-2026-62706)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds read in Microsoft Windows Media Foundation when processing a specially crafted file. A remote attacker can provide a specially crafted file for a user to open to execute arbitrary code.
8) Heap-based buffer overflow (CVE-ID: CVE-2026-62744)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Windows Media Foundation when opening a specially crafted file. A remote attacker can trick a user into opening a specially crafted file to execute arbitrary code.
User interaction is required to open a specially crafted file.
9) Authentication Bypass by Spoofing (CVE-ID: CVE-2026-62759)
CWE-ID: CWE-290 - Authentication Bypass by Spoofing
CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication by spoofing.
The vulnerability exists due to authentication bypass by spoofing in Windows Netlogon when communicating over an adjacent network. A remote attacker can manipulate a malicious link, application, or file to disguise it as a legitimate link or file to bypass authentication by spoofing.
Successful exploitation requires specific conditions, including particular protocol settings or configurations.
10) NULL pointer dereference (CVE-ID: CVE-2026-62762)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to null pointer dereference in Active Directory Domain Services when handling network requests. A remote user can send a network request to cause a denial of service.
11) Path traversal (CVE-ID: CVE-2026-62801)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security feature.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in Windows PowerShell when processing a pathname. A remote attacker can provide a crafted pathname to bypass a security feature.
User interaction is required for exploitation.
12) Heap-based buffer overflow (CVE-ID: CVE-2026-62810)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Active Directory Certificate Services (AD CS) when processing input. A local user can exploit the heap-based buffer overflow locally to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
13) Use-after-free (CVE-ID: CVE-2026-62813)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Active Directory Domain Services when handling network requests. A remote user can win a race condition to execute arbitrary code.
14) Race condition (CVE-ID: CVE-2026-68824)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to concurrent execution using a shared resource with improper synchronization (race condition) in Windows Connected User Experiences and Telemetry when concurrently accessing a shared resource. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
15) Use-after-free (CVE-ID: CVE-2026-68825)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in the Windows Bind Filter Driver when it is accessed locally. A local user can win a race condition to escalate privileges.
Successful exploitation can grant SYSTEM privileges.
16) Integer underflow (CVE-ID: CVE-2026-68827)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to integer underflow in Windows GDI+ when processing input. A remote user can trigger the integer underflow to elevate privileges.
User interaction is required, and successful exploitation can grant SYSTEM privileges.
17) Heap-based buffer overflow (CVE-ID: CVE-2026-68828)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Remote Desktop Client when processing a response from a malicious server. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
18) Link following (CVE-ID: CVE-2026-68830)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper link resolution before file access in Windows Universal Plug and Play (UPnP) Device Host when resolving links before accessing files. A local user can exploit the link-following behavior to disclose sensitive information.
The disclosed information can include file path information through unauthorized access to the file system.
19) Files or Directories Accessible to External Parties (CVE-ID: CVE-2026-68831)
CWE-ID: CWE-552 - Files or Directories Accessible to External Parties
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose file path information.
The vulnerability exists due to files or directories accessible to external parties in the Windows Defender Firewall Service when accessing files or directories associated with the service. A local user can access exposed file system paths to disclose file path information.
20) Integer overflow (CVE-ID: CVE-2026-68832)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Windows NTFS when handling NTFS operations. A local user can exploit the flaw locally to elevate privileges.
21) Heap-based buffer overflow (CVE-ID: CVE-2026-68833)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when conducting a physical attack. An attacker with physical access can perform a physical attack to execute arbitrary code.
22) Stack-based buffer overflow (CVE-ID: CVE-2026-68834)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Windows NTFS when handling network input. A remote user can send specially crafted network input to elevate privileges.
User interaction is required.
23) Use-after-free (CVE-ID: CVE-2026-68835)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Print Spooler Components when handling network requests. A remote user can exploit the use-after-free condition to elevate privileges.
User interaction is required for exploitation.
24) Use-after-free (CVE-ID: CVE-2026-68837)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows File History Service when attempting to win a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
25) Stack-based buffer overflow (CVE-ID: CVE-2026-68838)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Windows NTFS when handling network requests. A remote user can exploit the vulnerability to elevate privileges.
User interaction is required.
26) Heap-based buffer overflow (CVE-ID: CVE-2026-68839)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Windows USB Mass Storage Class Driver when an in-network attacker calls arbitrary endpoints. A remote attacker can call arbitrary endpoints to execute arbitrary code.
27) Race condition (CVE-ID: CVE-2026-68840)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a race condition in the Windows USB Driver when concurrently accessing a shared resource. A local user can win a race condition to escalate privileges.
Successful exploitation can grant SYSTEM privileges.
28) Heap-based buffer overflow (CVE-ID: CVE-2026-68841)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when processing NTFS data locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
29) Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-ID: CVE-2026-68842)
CWE-ID: CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module when accessing the service locally. A local user can exploit the vulnerability to disclose sensitive information.
Successful exploitation allows viewing heap memory from a privileged process running on the server.
30) Use-after-free (CVE-ID: CVE-2026-68843)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use-after-free in Microsoft Office Word when used locally. A local user can trigger the use-after-free condition to disclose sensitive information.
Successful exploitation can expose heap memory from a privileged process running on the server.
31) Heap-based buffer overflow (CVE-ID: CVE-2026-68844)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Storage Spaces Controller when processing input. A local user can trigger the heap-based buffer overflow to execute arbitrary code.
32) Heap-based buffer overflow (CVE-ID: CVE-2026-68845)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Program Compatibility Assistant Service when processing locally supplied input. A local user can exploit the buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
33) Use-after-free (CVE-ID: CVE-2026-68846)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Kernel when interacting with Windows Kernel over a network. A remote user can win a race condition to elevate privileges.
User interaction is required.
34) Use-after-free (CVE-ID: CVE-2026-68847)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Connected User Experiences and Telemetry when winning a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
35) Heap-based buffer overflow (CVE-ID: CVE-2026-68848)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Print Spooler Components when processing local input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
36) Out-of-bounds read (CVE-ID: CVE-2026-68849)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in the Windows Bluetooth Port Driver when accessed locally. A local user can win a race condition to disclose information.
Exploitation could expose heap memory from a privileged process running on the server.
37) Heap-based buffer overflow (CVE-ID: CVE-2026-68850)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Account when processing local input. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
38) Buffer over-read (CVE-ID: CVE-2026-68851)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to a buffer over-read in Windows NTFS when handling local operations. A local user can trigger the buffer over-read to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
39) Use of uninitialized resource (CVE-ID: CVE-2026-68852)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to use of an uninitialized resource in Microsoft Account when accessed locally. A local user can exploit the vulnerability to disclose information.
The disclosed information may include uninitialized heap memory.
40) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-68873)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to insertion of sensitive information into log files in Windows Program Compatibility Assistant Service when logging sensitive information. A local user can access log files containing sensitive information to disclose information.
The disclosed information may include uninitialized heap memory.
41) Out-of-bounds read (CVE-ID: CVE-2026-68874)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Program Compatibility Assistant Service when handling network requests. A remote user can send a specially crafted request to disclose sensitive information.
User interaction is required for exploitation. Disclosed information may include uninitialized heap memory.
42) Buffer over-read (CVE-ID: CVE-2026-68875)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute code locally.
The vulnerability exists due to a buffer over-read in Windows NTFS when processing NTFS data. A local user can process NTFS data to execute code locally.
No elevated privileges are required.
43) Heap-based buffer overflow (CVE-ID: CVE-2026-68876)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Program Compatibility Assistant Service when processing input over a network. A remote user can provide input to the service to escalate privileges.
User interaction is required.
44) Heap-based buffer overflow (CVE-ID: CVE-2026-68877)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Storage Spaces Controller when processing input. A local user can trigger the vulnerability to execute arbitrary code.
45) Stack-based buffer overflow (CVE-ID: CVE-2026-68878)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in the Windows Fast FAT Driver when handling network input. A remote user can exploit the vulnerability to elevate privileges.
User interaction is required; successful exploitation can result in SYSTEM privileges.
46) Heap-based buffer overflow (CVE-ID: CVE-2026-68880)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Win32K when handling input over a network. A remote user can exploit the heap-based buffer overflow to elevate privileges.
User interaction is required.
47) Out-of-bounds read (CVE-ID: CVE-2026-68881)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Standard XPS when processing XPS content locally. A local user can cause the out-of-bounds read to disclose information.
Successful exploitation could expose heap memory from a privileged process running on the server.
48) Heap-based buffer overflow (CVE-ID: CVE-2026-68884)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Kernel when processing local input. A local user can exploit a race condition to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
49) Heap-based buffer overflow (CVE-ID: CVE-2026-68885)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when used locally. A local user can trigger the overflow to elevate privileges.
50) Use-after-free (CVE-ID: CVE-2026-68886)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use-after-free in Windows Network Connection Broker when accessed locally. A local user can exploit the flaw to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
51) Out-of-bounds read (CVE-ID: CVE-2026-68887)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows Message Queuing Queue Manager when processing network requests. A remote attacker can send a network request to cause a denial of service.
52) Heap-based buffer overflow (CVE-ID: CVE-2026-68888)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when accessed locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
53) Heap-based buffer overflow (CVE-ID: CVE-2026-68889)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when handling network-based input. A remote user can exploit the heap-based buffer overflow to elevate privileges.
User interaction is required, and successful exploitation requires a deep understanding of the system.
54) Heap-based buffer overflow (CVE-ID: CVE-2026-68890)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when used locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
55) Out-of-bounds read (CVE-ID: CVE-2026-68891)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Standard XPS when processing XPS content. A local user can exploit the out-of-bounds read to disclose sensitive information.
Successful exploitation requires a deep understanding of the system and depends on environmental and system-configuration factors.
56) Heap-based buffer overflow (CVE-ID: CVE-2026-68892)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when processing input. A local user can provide crafted input to elevate privileges.
Successful exploitation may result in SYSTEM privileges.
57) Use-after-free (CVE-ID: CVE-2026-68893)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Remote Desktop Licensing Service when interacting with the service over a network. A remote user can win a race condition to elevate privileges.
User interaction is required, and successful exploitation can grant SYSTEM privileges.
58) Heap-based buffer overflow (CVE-ID: CVE-2026-68894)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Error Reporting when handling network requests. A remote user can send a specially crafted network request to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
59) Numeric Truncation Error (CVE-ID: CVE-2026-68895)
CWE-ID: CWE-197 - Numeric Truncation Error
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to numeric truncation error in Internet Storage Name Service when processing requests. A local user can exploit the numeric truncation error to disclose sensitive information.
Disclosed information can include file path information.
60) Absolute Path Traversal (CVE-ID: CVE-2026-68896)
CWE-ID: CWE-36 - Absolute Path Traversal
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to absolute path traversal in the Microsoft Windows Search Component when processing paths. A local user can exploit the path traversal vulnerability to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
61) Heap-based buffer overflow (CVE-ID: CVE-2026-68897)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when processing input. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation requires winning a race condition.
62) Out-of-bounds read (CVE-ID: CVE-2026-68898)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows iSCSI when processing network input. A remote attacker can send network input to cause a denial of service.
User interaction is required.
63) Out-of-bounds read (CVE-ID: CVE-2026-69265)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows NTFS when handling NTFS operations. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
64) Integer overflow (CVE-ID: CVE-2026-69266)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an integer overflow or wraparound in Windows DHCP Server when a user opens a specially crafted file. A remote attacker can provide a specially crafted file to execute arbitrary code.
65) Insufficient Granularity of Access Control (CVE-ID: CVE-2026-69267)
CWE-ID: CWE-1220 - Insufficient Granularity of Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose file path information.
The vulnerability exists due to insufficient granularity of access control in Windows Connected User Experiences and Telemetry when accessing file path information. A local user can access file path information beyond authorized permissions to disclose file path information.
66) Integer underflow (CVE-ID: CVE-2026-69269)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer underflow (wrap or wraparound) in Microsoft Standard XPS when processing input locally. A local user can exploit the integer underflow to elevate privileges.
A successful exploit could grant SYSTEM privileges.
67) Heap-based buffer overflow (CVE-ID: CVE-2026-69270)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows USB Audio Class driver (usbaudio.sys) when processing USB audio data. A local user can trigger the buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
68) Heap-based buffer overflow (CVE-ID: CVE-2026-69271)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when handling XPS content. A remote user can exploit the heap-based buffer overflow to elevate privileges.
User interaction is required for exploitation.
69) Heap-based buffer overflow (CVE-ID: CVE-2026-69272)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when processing XPS content. A remote user can exploit the vulnerability to elevate privileges.
Successful exploitation requires a deep understanding of the system and depends on environmental and configuration factors.
70) Use-after-free (CVE-ID: CVE-2026-69274)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Win32K when processing network-based input. A remote user can exploit the use-after-free condition to elevate privileges.
User interaction is required. Successful exploitation could result in SYSTEM privileges.
71) Use-after-free (CVE-ID: CVE-2026-69275)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Kernel Streaming WOW Thunk Service Driver when exploiting a race condition. A local user can win a race condition to elevate privileges.
72) Integer underflow (CVE-ID: CVE-2026-69276)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer underflow in the Microsoft UxTheme Library (uxtheme.dll) when handling calls to arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
73) Stack-based buffer overflow (CVE-ID: CVE-2026-69277)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) when handling input. A local user can exploit the buffer overflow to elevate privileges.
74) Use-after-free (CVE-ID: CVE-2026-69279)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Cloud Files Mini Filter Driver when handling local operations. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
75) Use-after-free (CVE-ID: CVE-2026-69280)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Push Notifications when handling notifications. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
76) Use-after-free (CVE-ID: CVE-2026-69281)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows License Manager when handling local operations. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
77) Heap-based buffer overflow (CVE-ID: CVE-2026-69283)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows CD-ROM Driver when handling CD-ROM operations. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
78) Heap-based buffer overflow (CVE-ID: CVE-2026-69284)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows DCOM Server when processing locally supplied input. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
79) Out-of-bounds read (CVE-ID: CVE-2026-69286)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in the Windows USB Audio Class driver (usbaudio.sys) when reading memory. A local user can trigger the out-of-bounds read to disclose information.
Successful exploitation can expose heap memory from a privileged process running on the server.
80) Use-after-free (CVE-ID: CVE-2026-69287)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Remote Desktop Services when attempting to win a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
81) Use of uninitialized resource (CVE-ID: CVE-2026-69288)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to use of an uninitialized resource in Windows GDI+ when processing resources locally. A local user can access uninitialized heap memory to disclose information.
82) Link following (CVE-ID: CVE-2026-69289)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to improper link resolution before file access in Windows Setup Files Cleanup when accessing files during cleanup. A local user can exploit the link-following flaw to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
83) Stack-based buffer overflow (CVE-ID: CVE-2026-69290)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Windows Storage Spaces Controller when handling input locally. A local user can trigger the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
84) Heap-based buffer overflow (CVE-ID: CVE-2026-69291)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Windows Volume Manager Extension Driver when processing a response from a malicious server. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code on the client system.
85) Double free (CVE-ID: CVE-2026-69292)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a double free in Remote Desktop Gateway Service when processing requests locally. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
86) Heap-based buffer overflow (CVE-ID: CVE-2026-69293)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing locally supplied input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
87) Information Exposure Through an Error Message (CVE-ID: CVE-2026-69294)
CWE-ID: CWE-209 - Information Exposure Through an Error Message
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to generation of error messages containing sensitive information in Microsoft COM for Windows when generating error messages. A local user can trigger the generation of an error message to disclose sensitive information.
Successful exploitation can expose heap memory from a privileged process running on the server.
88) Out-of-bounds read (CVE-ID: CVE-2026-69295)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in the Windows USB Driver when processing USB driver operations locally. A local user can trigger the out-of-bounds read to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
89) Use-after-free (CVE-ID: CVE-2026-69296)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Device Association Service when exploited over a network. A remote user can win a race condition to elevate privileges.
User interaction is required for exploitation.
90) Storing passwords in a recoverable format (CVE-ID: CVE-2026-69297)
CWE-ID: CWE-257 - Storing Passwords in a Recoverable Format
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose information.
The vulnerability exists due to storing passwords in a recoverable format in Windows DHCP Server when accessing the server over a network. A remote user can exploit this issue to disclose information.
The disclosed information may include heap memory from a privileged process running on the server.
91) Integer overflow (CVE-ID: CVE-2026-69298)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Windows Biometric Service when processing local requests. A local user can exploit the integer overflow or wraparound to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
92) Use-after-free (CVE-ID: CVE-2026-69299)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Microsoft COM for Windows when exploited locally. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
93) Use-after-free (CVE-ID: CVE-2026-69300)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Push Notifications when handling push notifications. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
94) Stack-based buffer overflow (CVE-ID: CVE-2026-69301)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Windows Win32K when handling network input. A remote user can trigger the overflow to elevate privileges.
User interaction is required.
95) Out-of-bounds read (CVE-ID: CVE-2026-69303)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in the Push Message Routing Service when the service is invoked locally. A local user can trigger the vulnerability to disclose information.
Successful exploitation could expose heap memory from a privileged process running on the server.
96) Use-after-free (CVE-ID: CVE-2026-69305)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in the Microsoft Windows Search Component when interacting with the component over a network and winning a race condition. A remote user can trigger the use-after-free condition to elevate privileges.
User interaction is required. Successful exploitation can grant SYSTEM privileges.
97) Heap-based buffer overflow (CVE-ID: CVE-2026-69307)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain SYSTEM privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows USB Audio Class driver (usbaudio.sys) when handling USB audio input. A local user can interact with the driver to gain SYSTEM privileges.
98) Out-of-bounds read (CVE-ID: CVE-2026-69308)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Standard XPS when processing input locally. A local user can process crafted input to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
99) Double free (CVE-ID: CVE-2026-69309)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a double free in Windows Print Spooler Components when handling print spooler operations. A local user can win a race condition to escalate privileges.
Successful exploitation can result in SYSTEM privileges.
100) Use-after-free (CVE-ID: CVE-2026-69310)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows DNS when exploiting a race condition locally. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
101) Use-after-free (CVE-ID: CVE-2026-69311)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows Audio Service when winning a race condition. A local user can exploit the race condition to elevate privileges.
102) Out-of-bounds read (CVE-ID: CVE-2026-69312)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to out-of-bounds read in Windows NTFS when processing NTFS data. A local user can exploit this flaw to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
103) Heap-based buffer overflow (CVE-ID: CVE-2026-69313)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when exploited over a network. A remote user can win a race condition to elevate privileges.
User interaction is required.
104) Use-after-free (CVE-ID: CVE-2026-69314)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows Device Association Broker service when handling network interactions. A remote user can win a race condition to elevate privileges.
User interaction is required.
105) Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-ID: CVE-2026-69315)
CWE-ID: CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Windows License Manager when accessed locally. A local user can access Windows License Manager to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
106) Buffer over-read (CVE-ID: CVE-2026-69316)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to a buffer over-read in Windows Overlay Filter when it is used locally. A local user can exploit the buffer over-read to disclose information.
Successful exploitation requires winning a race condition.
107) Out-of-bounds read (CVE-ID: CVE-2026-69317)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose file path information.
The vulnerability exists due to an out-of-bounds read in Remote Desktop Client when processing remote desktop connections. A remote user can trigger the out-of-bounds read to disclose file path information.
User interaction is required.
108) Out-of-bounds read (CVE-ID: CVE-2026-69318)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows Imaging Component when accessing memory outside the bounds of a buffer. A local user can trigger the out-of-bounds read to disclose information.
Disclosed information may include uninitialized heap memory.
109) Race condition (CVE-ID: CVE-2026-69319)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a race condition in the Windows USB Video Driver when concurrently executing using a shared resource. A local user can win a race condition to elevate privileges.
110) Missing Authentication for Critical Function (CVE-ID: CVE-2026-69321)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make unauthorized modifications to protected system data.
The vulnerability exists due to missing authentication for a critical function in Windows Power Dependency Coordinator when accessing a critical function locally. A local user can invoke the critical function to make unauthorized modifications to protected system data.
111) Double free (CVE-ID: CVE-2026-69322)
CWE-ID: CWE-415 - Double Free
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a double free in Microsoft Windows Search Component when handling network requests. A remote user can exploit the double-free condition to elevate privileges.
User interaction is required for exploitation. Successful exploitation could grant SYSTEM privileges.
112) Heap-based buffer overflow (CVE-ID: CVE-2026-69323)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when it is accessed locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
113) Type Confusion (CVE-ID: CVE-2026-69324)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain SYSTEM privileges.
The vulnerability exists due to type confusion in Windows Performance Monitor when accessing resources using incompatible types. A local user can access resources using incompatible types to gain SYSTEM privileges.
114) Heap-based buffer overflow (CVE-ID: CVE-2026-69325)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft JScript when handling calls to arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
Successful exploitation requires winning a race condition.
115) Untrusted search path (CVE-ID: CVE-2026-69328)
CWE-ID: CWE-426 - Untrusted Search Path
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges to SYSTEM privileges.
The vulnerability exists due to an untrusted search path in Windows Storage when using an untrusted search path. A local user can exploit the untrusted search path to elevate privileges to SYSTEM privileges.
116) Out-of-bounds read (CVE-ID: CVE-2026-69329)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in BranchCache when handling network requests. A remote attacker can send a specially crafted network request to cause a denial of service.
117) Use-after-free (CVE-ID: CVE-2026-69331)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Remote Access Connection Manager when exploiting a race condition locally. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
118) Out-of-bounds read (CVE-ID: CVE-2026-69332)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows NTFS when accessed over a network. A remote user can trigger the out-of-bounds read to elevate privileges.
User interaction is required for exploitation.
119) Use-after-free (CVE-ID: CVE-2026-69333)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Win32K when winning a race condition locally. A local user can exploit the race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
120) Heap-based buffer overflow (CVE-ID: CVE-2026-69334)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Windows Volume Manager Extension Driver when processing a malicious server response. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
User interaction is required.
121) Use-after-free (CVE-ID: CVE-2026-69335)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Win32K when winning a race condition during local exploitation. A local user can win a race condition to elevate privileges.
122) Heap-based buffer overflow (CVE-ID: CVE-2026-69336)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges to SYSTEM.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Standard XPS when handling network-based input. A remote user can exploit the heap-based buffer overflow to elevate privileges to SYSTEM.
User interaction is required.
123) Double free (CVE-ID: CVE-2026-69337)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a double free in Windows Registry when handling operations over a network. A remote user can win a race condition to elevate privileges.
User interaction is required for successful exploitation.
124) Use-after-free (CVE-ID: CVE-2026-69338)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in the Remote Desktop Gateway Service when processing network requests. A remote user can exploit the vulnerability to elevate privileges.
User interaction is required, and successful exploitation could result in SYSTEM privileges.
125) Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-ID: CVE-2026-69339)
CWE-ID: CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module when accessing the service locally. A local user can access the service to disclose sensitive information.
Successful exploitation allows viewing heap memory from a privileged process running on the server.
126) Heap-based buffer overflow (CVE-ID: CVE-2026-69340)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when handling NTFS operations over a network. A remote user can trigger the heap-based buffer overflow to elevate privileges.
User interaction is required, and successful exploitation depends on environmental and system-configuration factors.
127) Use-after-free (CVE-ID: CVE-2026-69341)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Image Acquisition when Windows Image Acquisition is used locally. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
128) Out-of-bounds read (CVE-ID: CVE-2026-69342)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when handling network requests. A remote attacker can send a specially crafted network request to cause a denial of service.
129) Out-of-bounds read (CVE-ID: CVE-2026-69343)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Overlay Filter when processing locally supplied input. A local user can trigger the out-of-bounds read to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
130) Out-of-bounds read (CVE-ID: CVE-2026-69344)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Print Spooler Components when processing local input. A local user can trigger the out-of-bounds read to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
131) Out-of-bounds read (CVE-ID: CVE-2026-69345)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Standard XPS when processing XPS content locally. A local user can exploit the out-of-bounds read to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
132) Heap-based buffer overflow (CVE-ID: CVE-2026-69346)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Print Spooler Components when processing network-supplied input. A remote user can send crafted input to the affected components over a network to elevate privileges.
User interaction is required for exploitation. Successful exploitation can result in SYSTEM privileges.
133) Heap-based buffer overflow (CVE-ID: CVE-2026-69347)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Windows Fast FAT Driver when accessing the system locally. A remote attacker can trigger the vulnerability locally to execute arbitrary code.
Successful exploitation requires a deep understanding of the system and depends on environmental and system-configuration factors.
134) Heap-based buffer overflow (CVE-ID: CVE-2026-69348)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Win32K when exploited locally. A local user can exploit the vulnerability to elevate privileges.
135) Use of uninitialized resource (CVE-ID: CVE-2026-69349)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose information.
The vulnerability exists due to use of an uninitialized resource in Windows Management Instrumentation when handling requests over a network. A remote user can send a crafted request to disclose information.
User interaction is required.
136) Heap-based buffer overflow (CVE-ID: CVE-2026-69350)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Overlay Filter when used locally. A local privileged user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
137) Exposure of Private Information ('Privacy Violation') (CVE-ID: CVE-2026-69351)
CWE-ID: CWE-359 - Exposure of Private Information ('Privacy Violation')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose file path information.
The vulnerability exists due to exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host when accessing the file system. A local user can access file path information to disclose file path information.
138) Heap-based buffer overflow (CVE-ID: CVE-2026-69352)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when invoked locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
139) Out-of-bounds read (CVE-ID: CVE-2026-69353)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Text Shaping when processing text-shaping data. A local user can trigger the out-of-bounds read to disclose sensitive information.
Successful exploitation could allow viewing heap memory from a privileged process running on the server.
140) Use-after-free (CVE-ID: CVE-2026-69357)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows NDIS when handling network traffic. A remote user can win a race condition to elevate privileges.
User interaction is required.
141) Use of uninitialized resource (CVE-ID: CVE-2026-69358)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use of an uninitialized resource in Remote Desktop Client when interacting with a remote desktop client over a network. A remote user can win a race condition to execute arbitrary code.
User interaction is required.
142) Heap-based buffer overflow (CVE-ID: CVE-2026-69359)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Active Directory Domain Services when handling input. A local user can exploit the buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
143) Heap-based buffer overflow (CVE-ID: CVE-2026-69360)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when opening a specially crafted file. A remote attacker can provide a specially crafted file to execute arbitrary code.
User interaction is required to open the crafted file.
144) Use-after-free (CVE-ID: CVE-2026-69362)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Error Reporting when winning a race condition. A local user can exploit the race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
145) Race condition (CVE-ID: CVE-2026-69364)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a race condition in Windows Print Spooler Components when concurrently executing operations use a shared resource. A remote user can win a race condition to elevate privileges.
User interaction is required.
146) Out-of-bounds read (CVE-ID: CVE-2026-69365)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) when processing network input. A remote user can trigger the out-of-bounds read to elevate privileges.
User interaction is required, and successful exploitation can grant SYSTEM privileges.
147) Use-after-free (CVE-ID: CVE-2026-69366)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows Kernel when exploiting a race condition over a network. A remote user can win the race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges. User interaction is required.
148) Out-of-bounds read (CVE-ID: CVE-2026-69367)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Standard XPS when processing XPS content. A local user can trigger the out-of-bounds read to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
149) Heap-based buffer overflow (CVE-ID: CVE-2026-69368)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Overlay Filter when it is accessed locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
150) Out-of-bounds read (CVE-ID: CVE-2026-69369)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows DNS when processing DNS data locally. A local user can cause Windows DNS to perform an out-of-bounds read to disclose information.
Successful exploitation could expose heap memory from a privileged process running on the server.
151) Heap-based buffer overflow (CVE-ID: CVE-2026-69371)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Overlay Filter when handling network requests. A remote user can send a specially crafted network request to elevate privileges.
User interaction is required.
152) Out-of-bounds read (CVE-ID: CVE-2026-69372)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows Network File System when processing network input. A remote user can trigger the out-of-bounds read to cause a denial of service.
User interaction is required.
153) Integer overflow (CVE-ID: CVE-2026-69373)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Windows Overlay Filter when processing crafted local input. A local privileged user can exploit the integer overflow or wraparound to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
154) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-69374)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Windows SMB Server when handling SMB requests over a network. A remote user can send requests that consume resources to cause a denial of service.
155) Out-of-bounds read (CVE-ID: CVE-2026-69376)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Standard XPS when accessed locally. A local user can exploit the out-of-bounds read to disclose sensitive information.
The disclosed data may include heap memory from a privileged process running on the server.
156) Missing Authorization (CVE-ID: CVE-2026-69377)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges to SYSTEM.
The vulnerability exists due to missing authorization in Windows Modern Device Management (MDM) when accessing MDM functionality locally. A local user can exploit the missing authorization to elevate privileges to SYSTEM.
157) Link following (CVE-ID: CVE-2026-69379)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to improper link resolution before file access (\'link following\') in Windows NTFS when accessing files through links. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
158) Out-of-bounds read (CVE-ID: CVE-2026-69381)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the Windows Storage Port Driver when subjected to a physical attack. An attacker with physical access can conduct a physical attack to disclose sensitive information.
Successful exploitation provides unintentional read access to kernel-space memory contents from a user-mode process.
159) External Control of File Name or Path (CVE-ID: CVE-2026-69383)
CWE-ID: CWE-73 - External Control of File Name or Path
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to external control of file name or path in Windows Shell when processing a file name or path. A local user can control a file name or path to elevate privileges.
Successful exploitation depends on environmental factors, system configuration, and additional security measures.
160) NULL pointer dereference (CVE-ID: CVE-2026-69384)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the Virtual Hard Disk (VHD) Miniport Driver when handling local operations. A remote attacker can trigger the null pointer dereference to cause a denial of service.
161) Race condition (CVE-ID: CVE-2026-69385)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a race condition in Windows TCP/IP when concurrently accessing a shared resource. A local user can win the race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
162) Heap-based buffer overflow (CVE-ID: CVE-2026-69386)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Windows Media Foundation when processing a specially crafted file. A remote attacker can provide a specially crafted file that a user opens to execute arbitrary code.
163) Use-after-free (CVE-ID: CVE-2026-69388)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows Bluetooth Service when winning a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation can elevate privileges from Medium Integrity Level to Local Service or SYSTEM.
164) Heap-based buffer overflow (CVE-ID: CVE-2026-69389)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Storage Management Provider when it is used locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
165) Out-of-bounds read (CVE-ID: CVE-2026-69390)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Spaceport.sys when accessing the driver locally. A local user can access the vulnerable driver to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
166) Stack-based buffer overflow (CVE-ID: CVE-2026-69391)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Windows Broker Infrastructure Service when processing input. A local user can exploit the stack-based buffer overflow to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
167) Use-after-free (CVE-ID: CVE-2026-69392)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Shell when winning a race condition. A local user can exploit the race condition to escalate privileges.
Successful exploitation can elevate privileges from a low integrity level in a contained sandboxed execution environment to a medium integrity level.
168) Out-of-bounds read (CVE-ID: CVE-2026-69393)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Spaceport.sys when accessed over a network. A remote user can trigger the out-of-bounds read to disclose sensitive information.
User interaction is required. Disclosed information may include kernel memory contents accessible from a user-mode process.
169) Heap-based buffer overflow (CVE-ID: CVE-2026-69394)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Audio Service when exploited locally. A local user can trigger the buffer overflow to elevate privileges.
Successful exploitation requires winning a race condition.
170) Format string error (CVE-ID: CVE-2026-69395)
CWE-ID: CWE-134 - Use of Externally-Controlled Format String
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose information.
The vulnerability exists due to use of externally-controlled format string in Active Directory Certificate Services (AD CS) when handling network requests. A remote user can submit a crafted format string to disclose information.
Successful exploitation could expose heap memory from a privileged process running on the server.
171) Use-after-free (CVE-ID: CVE-2026-69396)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows NDIS when handling network traffic. A remote user can win a race condition to elevate privileges.
User interaction is required.
172) Use-after-free (CVE-ID: CVE-2026-69397)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in OpenSSH for Windows when processing network input. A remote attacker can send specially crafted network input to execute arbitrary code.
User interaction is required.
173) Race condition (CVE-ID: CVE-2026-69398)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a race condition in Windows Bluetooth Service when executing concurrently using a shared resource. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
174) Use-after-free (CVE-ID: CVE-2026-69401)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Audio Video Control Transport Protocol when processing protocol operations. A local user can win a race condition to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
175) Missing Authorization (CVE-ID: CVE-2026-69403)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose heap memory from a privileged process running on the server.
The vulnerability exists due to missing authorization in Windows SMB Server when handling local SMB operations. A local user can access the server locally to disclose heap memory from a privileged process running on the server.
176) Race condition (CVE-ID: CVE-2026-69404)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a race condition in Windows TCP/IP when concurrently accessing a shared resource. A local user can win the race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
177) Memory leak (CVE-ID: CVE-2026-69405)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in Windows DHCP Server when handling DHCP requests over an adjacent network. A remote user can send DHCP requests to cause a denial of service.
178) Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-ID: CVE-2026-69406)
CWE-ID: CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Windows Kernel when accessing kernel memory from a user mode process. A local user can read kernel memory to disclose sensitive information.
179) Integer overflow (CVE-ID: CVE-2026-69407)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in the Volume Manager Driver when handling local input. A local user can exploit the integer overflow locally to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
180) Integer overflow (CVE-ID: CVE-2026-69408)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow or wraparound in Microsoft Windows Media Foundation when calling arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
181) Use-after-free (CVE-ID: CVE-2026-69410)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Win32K when winning a race condition. A local user can win a race condition to elevate privileges.
182) Stack-based buffer overflow (CVE-ID: CVE-2026-69412)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Windows DHCP Server when handling specially crafted requests over an adjacent network. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
183) Use-after-free (CVE-ID: CVE-2026-69413)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows USB Audio Class driver (usbaudio.sys) when handling USB audio. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
184) Missing Authentication for Critical Function (CVE-ID: CVE-2026-69415)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to missing authentication for critical function in Windows DHCP Server when handling network requests. A remote privileged user can access an insufficiently authenticated critical function to elevate privileges.
User interaction is required.
185) Buffer over-read (CVE-ID: CVE-2026-69416)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a buffer over-read in Windows DHCP Server when processing requests over an adjacent network. A remote user can trigger the buffer over-read to cause a denial of service.
186) Heap-based buffer overflow (CVE-ID: CVE-2026-69418)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Volume Manager Driver when handling network requests. A remote user can send a specially crafted network request to escalate privileges.
User interaction is required for exploitation. Successful exploitation could grant SYSTEM privileges.
187) Heap-based buffer overflow (CVE-ID: CVE-2026-69420)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows VOLSNAP.SYS when processing local input. A local user can exploit the heap-based buffer overflow to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
188) Integer underflow (CVE-ID: CVE-2026-69421)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer underflow in the Windows Kernel Mode Driver when accessing the driver locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
189) Use-after-free (CVE-ID: CVE-2026-69422)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in the Windows USB Video Driver when interacting with the driver locally. A local user can exploit the use-after-free to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
190) Heap-based buffer overflow (CVE-ID: CVE-2026-69423)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows USB Video Driver when accessed over a network. A remote user can exploit the vulnerability to escalate privileges.
User interaction is required. Successful exploitation can result in SYSTEM privileges.
191) Heap-based buffer overflow (CVE-ID: CVE-2026-69424)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Distributed File System (DFS) when processing local input. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
192) Link following (CVE-ID: CVE-2026-69425)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to modify protected system data.
The vulnerability exists due to improper link resolution before file access in Windows NTFS when accessing files through links. A local user can win a race condition to modify protected system data.
193) Heap-based buffer overflow (CVE-ID: CVE-2026-69426)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows VOLSNAP.SYS when executing code locally. A local user can execute code locally to execute arbitrary code.
194) Out-of-bounds read (CVE-ID: CVE-2026-69427)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows VOLSNAP.SYS when processing network input. A remote user can exploit the vulnerability to elevate privileges.
User interaction is required. Successful exploitation can result in SYSTEM privileges.
195) Out-of-bounds read (CVE-ID: CVE-2026-69428)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol when handling network requests. A remote attacker can send a specially crafted network request to cause a denial of service.
196) Heap-based buffer overflow (CVE-ID: CVE-2026-69429)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Windows IKE Extension when processing network traffic. A remote user can send specially crafted network traffic to execute arbitrary code.
Successful exploitation requires a deep understanding of the system and depends on environmental, configuration, and security-measure factors.
197) Use-after-free (CVE-ID: CVE-2026-69430)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Embedded Mode Service when winning a race condition. A local user can win a race condition to escalate privileges.
Successful exploitation can grant SYSTEM privileges.
198) Heap-based buffer overflow (CVE-ID: CVE-2026-69431)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Telnet Client when processing network input. A remote attacker can call arbitrary endpoints to execute arbitrary code.
199) Heap-based buffer overflow (CVE-ID: CVE-2026-69432)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Volume Manager Driver when handling input locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
200) Heap-based buffer overflow (CVE-ID: CVE-2026-69433)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Error Reporting when exploited locally. A local user can exploit the vulnerability locally to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
201) Heap-based buffer overflow (CVE-ID: CVE-2026-69434)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows URL Moniker when processing a specially crafted file. A remote attacker can cause a user to open a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file.
202) Heap-based buffer overflow (CVE-ID: CVE-2026-69436)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Error Reporting when handling data locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
203) Incorrect Conversion between Numeric Types (CVE-ID: CVE-2026-69438)
CWE-ID: CWE-681 - Incorrect Conversion between Numeric Types
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect conversion between numeric types in Microsoft JScript when calling arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
Successful exploitation requires a deep understanding of the system and depends on environmental and system-configuration factors.
204) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-69440)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges to SYSTEM privileges.
The vulnerability exists due to a time-of-check time-of-use (TOCTOU) race condition in the Windows MIDI Service Module when concurrent operations occur. A local user can win a race condition to elevate privileges to SYSTEM privileges.
205) Race condition (CVE-ID: CVE-2026-69441)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a race condition in Windows Installer when concurrently executing using a shared resource. A local user can win the race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
206) Out-of-bounds read (CVE-ID: CVE-2026-69443)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows Device Health Attestation (DHA) when handling network requests. A remote attacker can send a specially crafted network request to disclose information.
Successful exploitation could expose portions of process memory, including heap memory from a privileged process running on the server.
207) Heap-based buffer overflow (CVE-ID: CVE-2026-69444)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Windows Speech when handling speech-related data. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
208) Path traversal (CVE-ID: CVE-2026-69445)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in Windows Compressed Folder when handling a pathname. A local user can exploit path traversal to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
209) Heap-based buffer overflow (CVE-ID: CVE-2026-69447)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Audio Service when processing input. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
210) Race condition (CVE-ID: CVE-2026-69448)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to concurrent execution using a shared resource with improper synchronization (race condition) in Windows Bluetooth Service when concurrently accessing a shared resource. A local user can win a race condition to escalate privileges.
211) Heap-based buffer overflow (CVE-ID: CVE-2026-69449)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows BitLocker when invoked locally. A local privileged user can invoke the vulnerable functionality to execute arbitrary code.
212) Out-of-bounds read (CVE-ID: CVE-2026-69450)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows Error Reporting when processing local input. A local user can trigger the out-of-bounds read to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
213) Use-after-free (CVE-ID: CVE-2026-69451)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Management Instrumentation when processing network requests. A remote user can trigger the use-after-free condition to elevate privileges.
User interaction is required.
214) Missing Authorization (CVE-ID: CVE-2026-69453)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make unauthorized modifications to protected system data.
The vulnerability exists due to missing authorization in Microsoft Windows Search Component when performing local operations. A local user can exploit the missing authorization to make unauthorized modifications to protected system data.
215) Heap-based buffer overflow (CVE-ID: CVE-2026-69455)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Remote Access Connection Manager when handling input locally. A local user can exploit the vulnerability locally to elevate privileges.
Successful exploitation can elevate privileges from Medium Integrity Level to Local Service.
216) Heap-based buffer overflow (CVE-ID: CVE-2026-69456)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Windows Speech when processing input. A local user can trigger the overflow to escalate privileges.
217) Out-of-bounds read (CVE-ID: CVE-2026-69457)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in the Windows USB Driver when accessing the driver. A local user can trigger the out-of-bounds read to disclose information.
The disclosed information may include kernel memory contents accessible from a user-mode process.
218) Out-of-bounds read (CVE-ID: CVE-2026-69458)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows BitLocker when handling network requests. A remote user can send a specially crafted request to elevate privileges.
User interaction is required.
219) Heap-based buffer overflow (CVE-ID: CVE-2026-69459)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Power Dependency Coordinator when processing local input. A local user can exploit the buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
220) Use-after-free (CVE-ID: CVE-2026-69460)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Modern Device Management (MDM) when processing MDM operations over a network. A remote user can exploit the use-after-free condition to elevate privileges.
User interaction is required, and successful exploitation requires winning a race condition.
221) Stack-based buffer overflow (CVE-ID: CVE-2026-69461)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Windows NTFS when processing a specially crafted file opened by a user. A remote attacker can send a specially crafted file to a user to execute arbitrary code.
User interaction is required to open the specially crafted file.
222) Heap-based buffer overflow (CVE-ID: CVE-2026-69462)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Error Reporting when handling network requests. A remote user can send a specially crafted network request to elevate privileges.
Successful exploitation could grant SYSTEM privileges. User interaction is required.
223) Heap-based buffer overflow (CVE-ID: CVE-2026-69463)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when processing network requests. A remote attacker can call arbitrary endpoints to execute arbitrary code.
224) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-69466)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a time-of-check time-of-use race condition in the Windows Kernel when processing concurrent operations. A local user can win the race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
225) Stack-based buffer overflow (CVE-ID: CVE-2026-69467)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Graphics Component when processing crafted local input. A local user can exploit the buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
226) Heap-based buffer overflow (CVE-ID: CVE-2026-69468)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Volume Manager Extension Driver when processing crafted input. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation requires a deep understanding of the system and depends on environmental, system-configuration, and other security factors.
227) Integer overflow (CVE-ID: CVE-2026-69469)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in the Windows USB Audio Class driver (usbaudio.sys) when processing USB audio data. An attacker with physical access can perform a physical attack to elevate privileges.
User interaction is required. Successful exploitation could grant SYSTEM privileges.
228) Use-after-free (CVE-ID: CVE-2026-69470)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Connected User Experiences and Telemetry when handling local operations. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
229) Use-after-free (CVE-ID: CVE-2026-69472)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Devices Human Interface when exploiting a race condition locally. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
230) Use-after-free (CVE-ID: CVE-2026-69473)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows Kernel when accessed locally. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
231) Use-after-free (CVE-ID: CVE-2026-69474)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to use-after-free in Windows Overlay Filter when handling network requests. A remote user can win a race condition to disclose sensitive information.
User interaction is required.
232) Untrusted Pointer Dereference (CVE-ID: CVE-2026-69475)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to untrusted pointer dereference in Windows Remote Desktop Services when exploiting the service locally. A local user can exploit the untrusted pointer dereference to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
233) Heap-based buffer overflow (CVE-ID: CVE-2026-69476)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when used locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
234) Heap-based buffer overflow (CVE-ID: CVE-2026-69478)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Device Association Service when processing input locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
235) Heap-based buffer overflow (CVE-ID: CVE-2026-69479)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when processing NTFS operations locally. A remote attacker can trigger the heap-based buffer overflow locally to execute arbitrary code.
236) Heap-based buffer overflow (CVE-ID: CVE-2026-69480)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Partition Management Driver when interacting with the driver locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
237) Heap-based buffer overflow (CVE-ID: CVE-2026-69481)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges to SYSTEM.
The vulnerability exists due to a heap-based buffer overflow in Windows Enterprise App Management when handling network communications. A remote user can exploit the heap-based buffer overflow over a network to elevate privileges to SYSTEM.
User interaction is required.
238) Creation of temporary file in directory with insecure permissions (CVE-ID: CVE-2026-69482)
CWE-ID: CWE-379 - Creation of Temporary File in Directory with Insecure Permissions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make unauthorized modifications to protected system data.
The vulnerability exists due to creation of a temporary file in a directory with insecure permissions in Windows Error Reporting when creating temporary files. A local user can trigger the creation of a temporary file to make unauthorized modifications to protected system data.
239) Out-of-bounds read (CVE-ID: CVE-2026-69483)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Image Acquisition when processing input locally. A local user can trigger the out-of-bounds read to disclose sensitive information.
Successful exploitation may expose heap memory from a privileged process running on the server.
240) Use of uninitialized resource (CVE-ID: CVE-2026-69485)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use of an uninitialized resource in Remote Desktop Client when handling a specially crafted request over a network. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
241) Use-after-free (CVE-ID: CVE-2026-69488)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Device Association Service when processing requests locally. A local user can exploit the use-after-free condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
242) Heap-based buffer overflow (CVE-ID: CVE-2026-69489)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing local input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
243) Out-of-bounds read (CVE-ID: CVE-2026-69490)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to elevate privileges.
The vulnerability exists due to an out-of-bounds read in the Windows USB Mass Storage Class Driver when processing USB mass storage devices. An attacker with physical access can connect a malicious USB mass storage device to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
244) Heap-based buffer overflow (CVE-ID: CVE-2026-69491)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Microsoft DirectMusic when processing calls to arbitrary endpoints. A remote attacker can call arbitrary endpoints over a network to execute arbitrary code.
245) Heap-based buffer overflow (CVE-ID: CVE-2026-69492)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Partition Management Driver when processing locally supplied input. A local user can exploit the buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
246) Out-of-bounds read (CVE-ID: CVE-2026-69493)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds read in the Windows Event Logging Service when processing calls to arbitrary endpoints. A remote attacker can call arbitrary endpoints over a network to execute arbitrary code.
247) Out-of-bounds read (CVE-ID: CVE-2026-69494)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds read in Windows Event Logging Service when processing a response from a malicious server. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
User interaction is required.
248) Heap-based buffer overflow (CVE-ID: CVE-2026-69495)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Windows Event Logging Service when processing a response from a malicious server. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
User interaction is required.
249) Heap-based buffer overflow (CVE-ID: CVE-2026-69496)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Compressed Folder when handling network requests. A remote attacker can call arbitrary endpoints to execute arbitrary code.
250) Memory leak (CVE-ID: CVE-2026-69497)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in Windows DHCP Server when handling network requests. A remote user can send network requests to cause a denial of service.
251) Use-after-free (CVE-ID: CVE-2026-69498)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Win32K when exploiting a race condition locally. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
252) Integer overflow (CVE-ID: CVE-2026-69499)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow or wraparound in Windows Imaging Component when processing a specially crafted file. A remote attacker can trick a user into opening a specially crafted file to execute arbitrary code.
253) Use-after-free (CVE-ID: CVE-2026-69500)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Image Acquisition when winning a race condition locally. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
254) Untrusted Pointer Dereference (CVE-ID: CVE-2026-69501)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to untrusted pointer dereference in Windows Secure Kernel Mode when handling locally initiated operations. A local user can exploit the vulnerability locally to elevate privileges.
Successful exploitation requires sustained low-memory conditions on the target system.
255) Stack-based buffer overflow (CVE-ID: CVE-2026-69503)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Windows USB Driver when processing crafted data over a network with user interaction. A remote user can send specially crafted data to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
256) Out-of-bounds read (CVE-ID: CVE-2026-69504)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows NTFS when handling NTFS operations. A local user can access the vulnerable NTFS functionality locally to disclose information.
Successful exploitation could allow viewing heap memory from a privileged process running on the server.
257) Out-of-bounds read (CVE-ID: CVE-2026-69505)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows NTFS when processing network requests. A remote user can exploit the out-of-bounds read to elevate privileges.
User interaction is required for exploitation. Successful exploitation could grant SYSTEM privileges.
258) File And Directory Information Exposure (CVE-ID: CVE-2026-69507)
CWE-ID: CWE-538 - File And Directory Information Exposure
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into an externally-accessible file or directory in Microsoft Windows Search Component when accessing an externally-accessible file or directory over a network. A remote user can access the externally-accessible file or directory to disclose sensitive information.
User interaction is required. Successful exploitation may expose heap memory from a privileged process running on the server.
259) Stack-based buffer overflow (CVE-ID: CVE-2026-69508)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a stack-based buffer overflow in the Windows MIDI Service Module when processing locally supplied input. A local user can exploit the buffer overflow to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
260) Heap-based buffer overflow (CVE-ID: CVE-2026-69509)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Fax Service when exploited locally. A local user can exploit the heap-based buffer overflow locally to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
261) Stack-based buffer overflow (CVE-ID: CVE-2026-69510)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Windows DHCP Server when processing specially crafted packets. A remote attacker can send a specially crafted packet to the affected service to execute arbitrary code.
Successful exploitation requires specific protocol settings or configurations.
262) Heap-based buffer overflow (CVE-ID: CVE-2026-69511)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Windows Media Foundation when processing a specially crafted file. A remote attacker can provide a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file.
263) Heap-based buffer overflow (CVE-ID: CVE-2026-69512)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Spaceport.sys when handling network requests. A remote user can send a specially crafted network request to elevate privileges.
User interaction is required for exploitation.
264) Heap-based buffer overflow (CVE-ID: CVE-2026-69513)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Error Reporting when exploiting the vulnerability locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
265) Heap-based buffer overflow (CVE-ID: CVE-2026-69514)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Remote Desktop Services when handling network input. A remote user can interact with Remote Desktop Services over a network to execute arbitrary code.
Successful exploitation requires a deep understanding of the system and depends on environmental and system-configuration factors.
266) Use-after-free (CVE-ID: CVE-2026-69516)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Connected Devices Platform Service (Cdpsvc) when a race condition is triggered. A local user can win a race condition to elevate privileges.
Successful exploitation can elevate privileges from Medium Integrity Level to Local Service.
267) Use-after-free (CVE-ID: CVE-2026-69517)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Wireless Networking when handling wireless networking operations. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
268) Heap-based buffer overflow (CVE-ID: CVE-2026-69518)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Remote Desktop when processing specially crafted clipboard data in a Remote Desktop sharing session. A remote attacker can join a Remote Desktop sharing session and send specially crafted clipboard data to execute arbitrary code.
User interaction is required to initiate or participate in the sharing session.
269) Use-after-free (CVE-ID: CVE-2026-69524)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Active Directory Domain Services when processing a specially crafted packet. A remote attacker can send a specially crafted packet to execute arbitrary code.
Successful exploitation requires winning a race condition.
270) Use-after-free (CVE-ID: CVE-2026-69525)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Remote Desktop Services when calling arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
271) Out-of-bounds read (CVE-ID: CVE-2026-69527)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the Windows USB Mass Storage Class Driver when processing USB mass storage devices. A local user can exploit the out-of-bounds read to disclose sensitive information.
Disclosed information may include file path information.
272) Missing Authentication for Critical Function (CVE-ID: CVE-2026-69528)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to missing authentication for a critical function in Windows Shell when accessing the critical function locally. A local user can exploit the missing authentication to escalate privileges.
273) Use-after-free (CVE-ID: CVE-2026-69530)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Reliable Multicast Transport Driver (RMCAST) when handling a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
Successful exploitation requires winning a race condition.
274) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-69531)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make unauthorized modifications to protected system data.
The vulnerability exists due to an unintended proxy or intermediary (\'confused deputy\') in Microsoft Windows Speech when triggering the vulnerability locally. A local user can trigger the vulnerability to make unauthorized modifications to protected system data.
275) Out-of-bounds read (CVE-ID: CVE-2026-69532)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows NTFS when it is accessed locally. A local user can trigger the out-of-bounds read to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
276) Command injection (CVE-ID: CVE-2026-69534)
CWE-ID: CWE-77 - Command injection
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to improper neutralization of special elements used in a command in Windows Program Compatibility Assistant Service when processing commands. A local user can inject commands to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
277) Numeric Truncation Error (CVE-ID: CVE-2026-69535)
CWE-ID: CWE-197 - Numeric Truncation Error
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to numeric truncation error in Windows Spaceport.sys when processing numeric values. A local user can exploit the numeric truncation error to elevate privileges.
278) Use-after-free (CVE-ID: CVE-2026-69536)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Remote Desktop Services when handling network connections. A remote user can win a race condition to execute arbitrary code.
User interaction is required.
279) Out-of-bounds read (CVE-ID: CVE-2026-69538)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to an out-of-bounds read in Windows Spaceport.sys when handling input. A local user can trigger the vulnerability to execute arbitrary code.
280) Use-after-free (CVE-ID: CVE-2026-69539)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Remote Desktop Services when handling network connections. A remote user can win a race condition to execute arbitrary code.
281) Use-after-free (CVE-ID: CVE-2026-69540)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Audio Service when exploiting a race condition locally. A local user can win a race condition to escalate privileges.
Successful exploitation can grant SYSTEM privileges.
282) Heap-based buffer overflow (CVE-ID: CVE-2026-69541)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver when handling local input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
283) Heap-based buffer overflow (CVE-ID: CVE-2026-69542)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Camera Frame Server Monitor when processing local input. A local user can exploit the overflow to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
284) Heap-based buffer overflow (CVE-ID: CVE-2026-69544)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows SMB Client when handling SMB client operations locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
285) Use-after-free (CVE-ID: CVE-2026-69546)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Active Directory Domain Services when calling arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
Successful exploitation requires winning a race condition.
286) Heap-based buffer overflow (CVE-ID: CVE-2026-69547)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows DHCP Server when handling specially crafted requests. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
287) Heap-based buffer overflow (CVE-ID: CVE-2026-69548)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to disclose information.
The vulnerability exists due to a heap-based buffer overflow in Windows RNDIS when conducting a physical attack. An attacker with physical access can conduct a physical attack to disclose information.
The disclosed information may include kernel memory content.
288) Out-of-bounds read (CVE-ID: CVE-2026-69549)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in the Virtual Hard Disk (VHD) Miniport Driver when it is accessed locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation depends on system-specific factors, including the environment and system configuration.
289) Use-after-free (CVE-ID: CVE-2026-69551)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows DNS when handling a specially crafted request. A remote user can send a specially crafted request to execute arbitrary code.
Exploitation requires low-level access to an affected server; user interaction is not required.
290) Information Exposure Through an Error Message (CVE-ID: CVE-2026-69552)
CWE-ID: CWE-209 - Information Exposure Through an Error Message
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to generation of error messages containing sensitive information in Windows Print Spooler Components when handling network requests. A remote user can trigger an error message to disclose sensitive information.
User interaction is required for exploitation.
291) Missing Authorization (CVE-ID: CVE-2026-69553)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to missing authorization in Windows Hyper-V when exploiting a race condition over a network. A remote user can win a race condition to elevate privileges.
User interaction is required.
292) Missing Authentication for Critical Function (CVE-ID: CVE-2026-69554)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make unauthorized modifications to protected system data.
The vulnerability exists due to missing authentication for a critical function in the Microsoft Windows Search Component when invoking a critical function. A local user can invoke the critical function to make unauthorized modifications to protected system data.
293) Use-after-free (CVE-ID: CVE-2026-69560)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows Work Folder Service when using the service. A local user can exploit the use-after-free to elevate privileges.
Successful exploitation requires winning a race condition and can result in SYSTEM privileges.
294) Out-of-bounds read (CVE-ID: CVE-2026-69561)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in the Windows CD-ROM Driver when accessing the driver locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
295) Heap-based buffer overflow (CVE-ID: CVE-2026-69563)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Program Compatibility Assistant Service when the service is accessed locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation requires winning a race condition and can result in SYSTEM privileges.
296) Heap-based buffer overflow (CVE-ID: CVE-2026-69564)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) when processing OCSP data locally. A local user can exploit the heap-based buffer overflow to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
297) Heap-based buffer overflow (CVE-ID: CVE-2026-69566)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when conducting a physical attack. An attacker with physical access can exploit the vulnerability to execute arbitrary code.
298) Use-after-free (CVE-ID: CVE-2026-69567)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows NTFS when handling NTFS operations. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
299) Out-of-bounds read (CVE-ID: CVE-2026-69568)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows Storage Spaces Controller when processing locally supplied input. A local user can trigger the out-of-bounds read to disclose information.
Disclosed information may include kernel memory contents accessible from a user-mode process.
300) Untrusted Pointer Dereference (CVE-ID: CVE-2026-69569)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to untrusted pointer dereference in Windows Print Spooler Components when handling network requests. A remote user can send a network request to cause a denial of service.
User interaction is required.
301) Heap-based buffer overflow (CVE-ID: CVE-2026-69571)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows USB Audio Class driver (usbaudio.sys) when processing USB audio input. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
302) Out-of-bounds read (CVE-ID: CVE-2026-69572)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows SMB Client when processing SMB network traffic. A remote user can trigger the out-of-bounds read to disclose information.
The disclosed information may include kernel memory contents. User interaction is required.
303) Use-after-free (CVE-ID: CVE-2026-69573)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows Universal Disk Format File System Driver (UDFS) when processing UDFS file system data. A local user can win a race condition to trigger the use-after-free and elevate privileges.
Successful exploitation could result in SYSTEM privileges.
304) Use-after-free (CVE-ID: CVE-2026-69574)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Device Association Service when a race condition is won. A local user can win a race condition to escalate privileges.
Successful exploitation can result in SYSTEM privileges.
305) Use-after-free (CVE-ID: CVE-2026-69575)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Storage Spaces Controller when winning a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
306) Use-after-free (CVE-ID: CVE-2026-69576)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Graphic Fonts when processing graphics fonts locally. A local user can trigger the use-after-free to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
307) Numeric Truncation Error (CVE-ID: CVE-2026-69578)
CWE-ID: CWE-197 - Numeric Truncation Error
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to numeric truncation error in Windows Kernel when processing numeric values. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
308) Use-after-free (CVE-ID: CVE-2026-69579)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Message Queuing when processing a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
No user interaction is required.
309) Heap-based buffer overflow (CVE-ID: CVE-2026-69580)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Biometric Service when interacting with the service locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
310) Use-after-free (CVE-ID: CVE-2026-69581)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Device Association Service when processing local operations. A local user can win a race condition to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
311) Buffer over-read (CVE-ID: CVE-2026-69582)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a buffer over-read in the Windows Volume Manager Extension Driver when invoked locally. A local user can exploit the buffer over-read to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
312) Heap-based buffer overflow (CVE-ID: CVE-2026-69583)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when accessing the service locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
313) Integer overflow (CVE-ID: CVE-2026-69584)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Windows USB Video Driver when processing input locally. A local user can trigger the integer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
314) Type conversion (CVE-ID: CVE-2026-69585)
CWE-ID: CWE-704 - Type conversion
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to incorrect type conversion or cast in the Microsoft Windows Search Component when processing data locally. A local user can exploit the incorrect type conversion or cast to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
315) Integer overflow (CVE-ID: CVE-2026-69586)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow or wraparound in Microsoft Windows PDF when processing calls to arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints over a network to execute arbitrary code.
316) NULL pointer dereference (CVE-ID: CVE-2026-69587)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in Windows IKE Extension when handling network requests. A remote attacker can send a network request to cause a denial of service.
317) Memory leak (CVE-ID: CVE-2026-69588)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in Windows TCP/IP when handling network traffic. A remote attacker can send network traffic to cause a denial of service.
318) Heap-based buffer overflow (CVE-ID: CVE-2026-69589)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when it is accessed locally. A local user can exploit the vulnerability locally to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
319) Heap-based buffer overflow (CVE-ID: CVE-2026-69590)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) when handling specially crafted network packets. A remote attacker can send a specially crafted packet to the affected service to execute arbitrary code.
No user interaction is required.
320) Out-of-bounds read (CVE-ID: CVE-2026-69591)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows NTFS when processing crafted network content. A remote user can provide crafted network content to disclose sensitive information.
Successful exploitation can expose kernel memory contents to a user-mode process and requires user interaction.
321) Heap-based buffer overflow (CVE-ID: CVE-2026-69592)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Universal Disk Format File System Driver (UDFS) when operating locally. A local user can trigger the heap-based buffer overflow locally to escalate privileges.
Successful exploitation could result in SYSTEM privileges.
322) Heap-based buffer overflow (CVE-ID: CVE-2026-69593)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing data. A local user can trigger the overflow to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
323) Heap-based buffer overflow (CVE-ID: CVE-2026-69594)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) when processing local input. A local user can exploit the buffer overflow to escalate privileges.
Successful exploitation can grant SYSTEM privileges.
324) Use-after-free (CVE-ID: CVE-2026-69595)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Windows Services for NFS ONCRPC XDR Driver when processing a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
325) Use-after-free (CVE-ID: CVE-2026-69597)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows HTTP.sys when handling network requests. A remote user can interact with Windows HTTP.sys over a network to elevate privileges.
User interaction is required, and successful exploitation requires winning a race condition.
326) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2026-69598)
CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect calculation of buffer size in Windows iSCSI when processing a response from a malicious server. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
327) Use-after-free (CVE-ID: CVE-2026-69599)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Remote Desktop Services when handling network requests. A remote user can win a race condition to execute arbitrary code.
328) Use-after-free (CVE-ID: CVE-2026-69600)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Microsoft Windows Search Component when processing locally initiated operations. A local user can exploit the use-after-free condition to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
329) Heap-based buffer overflow (CVE-ID: CVE-2026-69601)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Windows Media Foundation when processing a specially crafted file. A remote attacker can provide a specially crafted file for a user to open to execute arbitrary code.
User interaction is required.
330) Use-after-free (CVE-ID: CVE-2026-69602)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows PrintWorkflowUserSvc when exploited over a network. A remote user can win a race condition to elevate privileges.
User interaction is required for successful exploitation.
331) Heap-based buffer overflow (CVE-ID: CVE-2026-69603)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Windows Hyper-V hypervisor when processing a specially crafted hypercall with a malformed payload size. A local user can issue a specially crafted hypercall to execute arbitrary code.
Exploitation requires running code within a virtualized environment.
332) Heap-based buffer overflow (CVE-ID: CVE-2026-69604)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Audio Service when processing locally supplied input. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
333) Use-after-free (CVE-ID: CVE-2026-69605)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Microsoft Install Service when winning a race condition locally. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
334) Use-after-free (CVE-ID: CVE-2026-69606)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Shell when a race condition is won. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
335) Use-after-free (CVE-ID: CVE-2026-69607)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Deployment Services when handling network traffic. A remote attacker can trigger the use-after-free condition over a network to execute arbitrary code.
User interaction is required for successful exploitation.
336) Integer overflow (CVE-ID: CVE-2026-69608)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Microsoft Windows Search Component when processing local input. A local user can exploit the integer overflow or wraparound to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
337) Out-of-bounds read (CVE-ID: CVE-2026-69609)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows Win32K when processing local input. A local user can trigger the out-of-bounds read to disclose information.
Successfully exploiting the vulnerability could expose heap memory from a privileged process running on the server.
338) Buffer over-read (CVE-ID: CVE-2026-69610)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a buffer over-read in Windows Win32K when processing locally supplied input. A local user can exploit the buffer over-read to escalate privileges.
Successful exploitation could result in SYSTEM privileges.
339) Use-after-free (CVE-ID: CVE-2026-69611)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Virtual Hard Disk (VHD) Miniport Driver when exploiting the driver locally. A local user can exploit the use-after-free condition to elevate privileges.
Successful exploitation requires winning a race condition and can result in SYSTEM privileges.
340) Absolute Path Traversal (CVE-ID: CVE-2026-69612)
CWE-ID: CWE-36 - Absolute Path Traversal
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to absolute path traversal in Windows Error Reporting when handling a path. A local user can provide a crafted path to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
341) Use-after-free (CVE-ID: CVE-2026-69613)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Image Acquisition when a race condition is won. A local user can win a race condition to elevate privileges.
The elevated privileges are SYSTEM privileges.
342) Out-of-bounds read (CVE-ID: CVE-2026-69616)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Remote Desktop Services when accessing the service locally. A local user can trigger the out-of-bounds read to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
343) Out-of-bounds read (CVE-ID: CVE-2026-69617)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows Resilient File System (ReFS) when processing filesystem data. A local user can exploit the out-of-bounds read to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
344) Out-of-bounds read (CVE-ID: CVE-2026-69618)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows SMB Client when processing SMB client operations. A local user can trigger the out-of-bounds read to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
345) Out-of-bounds read (CVE-ID: CVE-2026-69619)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows exFAT File System when accessed over a network. A remote user can exploit the out-of-bounds read to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
346) Stack-based buffer overflow (CVE-ID: CVE-2026-69620)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Windows DHCP Server when calling arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
347) Heap-based buffer overflow (CVE-ID: CVE-2026-69621)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Fax Service when processing input. A local user can trigger the heap-based buffer overflow to escalate privileges.
Successful exploitation can elevate privileges from Medium Integrity Level to Local Service.
348) Heap-based buffer overflow (CVE-ID: CVE-2026-69623)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows HTTP Print Provider when processing a specially crafted file. A remote user can trick a victim into opening a specially crafted file to execute arbitrary code.
349) Incomplete List of Disallowed Inputs (CVE-ID: CVE-2026-69624)
CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to make unauthorized modifications to protected system data.
The vulnerability exists due to an incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) when handling network requests. A remote user can submit disallowed input to make unauthorized modifications to protected system data.
350) Heap-based buffer overflow (CVE-ID: CVE-2026-69625)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to gain SYSTEM privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Connected User Experiences and Telemetry when handling network input. A remote user can exploit the vulnerability to gain SYSTEM privileges.
User interaction is required.
351) Out-of-bounds read (CVE-ID: CVE-2026-69627)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in the Windows Remote Desktop Licensing Service when the service is accessed locally. A local user can trigger the out-of-bounds read to disclose information.
Successful exploitation can expose heap memory from a privileged process running on the server.
352) Heap-based buffer overflow (CVE-ID: CVE-2026-69628)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows iSCSI when handling specially crafted network requests. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
353) Out-of-bounds read (CVE-ID: CVE-2026-69630)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges to SYSTEM.
The vulnerability exists due to an out-of-bounds read in Windows Win32K when accessing the component. A local user can trigger the out-of-bounds read to elevate privileges to SYSTEM.
Successful exploitation requires winning a race condition.
354) Integer overflow (CVE-ID: CVE-2026-69631)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow or wraparound in Windows DNS when handling network requests. A remote attacker can send a specially crafted network request to cause a denial of service.
355) Out-of-bounds read (CVE-ID: CVE-2026-69637)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when processing input over an adjacent network. A remote user can provide input that triggers the out-of-bounds read to cause a denial of service.
356) Heap-based buffer overflow (CVE-ID: CVE-2026-69638)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when handling NTFS data. A remote attacker can trigger the vulnerability to execute arbitrary code.
357) Heap-based buffer overflow (CVE-ID: CVE-2026-69643)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Spaceport.sys when processing network-supplied input. A remote user can provide crafted input to elevate privileges.
User interaction is required for exploitation.
358) Use-after-free (CVE-ID: CVE-2026-69645)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Message Queuing when processing Message Queuing operations. A local user can trigger the use-after-free condition to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
359) Use-after-free (CVE-ID: CVE-2026-69648)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Notification when using Windows Notification. A local user can exploit the use-after-free to elevate privileges.
Successful exploitation requires winning a race condition.
360) Use-after-free (CVE-ID: CVE-2026-69652)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Win32K when it is accessed locally. A local user can exploit the use-after-free condition to elevate privileges.
Successful exploitation requires winning a race condition.
361) Use-after-free (CVE-ID: CVE-2026-69654)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Accounts Control when exploiting the component locally. A local user can exploit the use-after-free to elevate privileges.
362) Heap-based buffer overflow (CVE-ID: CVE-2026-69669)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Windows Kernel when processing specially crafted Xpress LZ-compressed data through SMB. A remote attacker can cause an affected system to process specially crafted Xpress LZ-compressed data through SMB to execute arbitrary code.
User interaction is not required.
363) Use of uninitialized resource (CVE-ID: CVE-2026-69672)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use of an uninitialized resource in Windows DNS when accessed locally. A local user can trigger the use of an uninitialized resource to disclose sensitive information.
Disclosed information may include heap memory from a privileged process running on the server.
364) Missing Authentication for Critical Function (CVE-ID: CVE-2026-69674)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass a security feature.
The vulnerability exists due to missing authentication for critical function in Windows Modern Device Management (MDM) when invoking a critical function. A local user can cause an enrolled device management provider to become inactive to bypass a security feature.
This can prevent centrally managed policies from being enforced on the enrolled device.
365) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-69676)
CWE-ID: CWE-294 - Authentication Bypass by Capture-replay
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to authentication bypass by capture-replay in Windows Kerberos when handling authentication requests. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
366) Out-of-bounds read (CVE-ID: CVE-2026-69679)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when processing DHCP requests. A remote user can send a crafted DHCP request to cause a denial of service.
367) Origin validation error (CVE-ID: CVE-2026-69680)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform DNS spoofing.
The vulnerability exists due to an origin validation error in Windows DNS when validating signed DNS zone records. A remote attacker can cause an affected DNS server to accept forged DNS records for a different zone as valid to perform DNS spoofing.
Exploitation requires specific protocol settings or configurations and control of a signed DNS zone.
368) Heap-based buffer overflow (CVE-ID: CVE-2026-69681)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges to SYSTEM.
The vulnerability exists due to a heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver when handling crafted input received over a network. A remote user can provide crafted input over a network to elevate privileges to SYSTEM.
User interaction is required.
369) Use-after-free (CVE-ID: CVE-2026-69682)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Host Guardian Service when processing local requests. A local user can exploit the use-after-free to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
370) Information Exposure Through an Error Message (CVE-ID: CVE-2026-69684)
CWE-ID: CWE-209 - Information Exposure Through an Error Message
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to generation of error messages containing sensitive information in Windows Error Reporting when generating error messages. A local user can view an error message containing sensitive information to disclose sensitive information.
The disclosed information may include heap memory from a privileged process running on the server.
371) Heap-based buffer overflow (CVE-ID: CVE-2026-69685)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Kerberos when handling local input. A local user can interact with the vulnerable component locally to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
372) Integer underflow (CVE-ID: CVE-2026-69687)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer underflow in the Windows USB Audio Class driver (usbaudio.sys) when handling USB audio data. A local user can exploit the vulnerability locally to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
373) Heap-based buffer overflow (CVE-ID: CVE-2026-69688)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Encrypting File System (EFS) when handling network requests. A remote user can send network requests to elevate privileges.
User interaction is required, and successful exploitation depends on environmental and system-configuration factors.
374) Out-of-bounds read (CVE-ID: CVE-2026-69689)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to an out-of-bounds read in Windows Win32K when exploited over a network. A remote user can exploit the vulnerability to escalate privileges.
User interaction is required.
375) Heap-based buffer overflow (CVE-ID: CVE-2026-69691)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Spaceport.sys when handling locally supplied input. A local user can exploit the buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
376) Use-after-free (CVE-ID: CVE-2026-69692)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Audio Service when a race condition is won. A local user can win a race condition to elevate privileges.
SYSTEM is the privilege level obtainable upon successful exploitation.
377) Use-after-free (CVE-ID: CVE-2026-69693)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in the Windows Device Association Broker service when winning a race condition. A local user can win a race condition to escalate privileges.
Successful exploitation can grant SYSTEM privileges.
378) Deserialization of Untrusted Data (CVE-ID: CVE-2026-69694)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to deserialization of untrusted data in the Windows IP Address Management (IPAM) Service when deserializing untrusted data. A local user can provide untrusted serialized data to the service to elevate privileges.
379) Use-after-free (CVE-ID: CVE-2026-69706)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Win32K when a race condition is triggered over a network. A remote user can win a race condition to elevate privileges.
User interaction is required for exploitation.
380) Integer overflow (CVE-ID: CVE-2026-69707)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in the Windows USB Audio Class driver (usbaudio.sys) when handling USB audio class driver operations. A local user can exploit the integer overflow to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
381) Use-after-free (CVE-ID: CVE-2026-69708)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Web Platform Storage when exploiting a race condition locally. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
382) Heap-based buffer overflow (CVE-ID: CVE-2026-69709)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when handling NTFS data. A local user can trigger the overflow to execute arbitrary code.
383) Race condition (CVE-ID: CVE-2026-69710)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to a race condition in Windows Hello when concurrently accessing a shared resource. A local privileged user can win the race condition to elevate privileges.
Successful exploitation can result in Virtual Trust Level 1 (VTL1) privileges.
384) Use-after-free (CVE-ID: CVE-2026-69711)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Device Association Service when exploiting a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
385) Use-after-free (CVE-ID: CVE-2026-69712)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Key Distribution Center when processing a specially crafted request. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
386) Dependency on vulnerable third-party component (CVE-ID: CVE-2026-69713)
CWE-ID: CWE-1395 - Dependency on Vulnerable Third-Party Component
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to bypass UEFI Secure Boot.
The vulnerability exists due to dependency on a vulnerable third-party component in Windows Secure Boot when the system starts. A local privileged user can exploit the vulnerable component to bypass UEFI Secure Boot.
Successful exploitation can allow untrusted code to run early in the boot process, before operating-system protections are active.
387) Stack-based buffer overflow (CVE-ID: CVE-2026-69714)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Windows Device Association Service when handling network requests. A remote user can send a specially crafted network request to elevate privileges.
User interaction is required for exploitation.
388) Out-of-bounds read (CVE-ID: CVE-2026-69715)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds read in Windows Direct Show when handling calls to arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints over a network to execute arbitrary code.
389) Untrusted Pointer Dereference (CVE-ID: CVE-2026-69717)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to untrusted pointer dereference in Windows Group Policy when processing Group Policy data over a network. A remote user can exploit the vulnerability over a network to elevate privileges.
User interaction is required. Successful exploitation could result in SYSTEM privileges.
390) Heap-based buffer overflow (CVE-ID: CVE-2026-69720)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows MIDI Service Module when processing locally supplied input. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
391) Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-ID: CVE-2026-69723)
CWE-ID: CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in the Windows Kernel when accessed over a network. A remote user can access the vulnerable functionality over a network to disclose sensitive information.
User interaction is required.
392) Double free (CVE-ID: CVE-2026-69725)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a double free in Windows Hello when Windows Hello is used. A local user can win a race condition to elevate privileges.
393) Heap-based buffer overflow (CVE-ID: CVE-2026-69727)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when handling network requests. A remote user can send a specially crafted request to elevate privileges.
User interaction is required for exploitation. Successful exploitation could result in SYSTEM privileges.
394) Heap-based buffer overflow (CVE-ID: CVE-2026-69729)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Credential Providers when handling a specially crafted network request. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
395) Use-after-free (CVE-ID: CVE-2026-69730)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows DNS when processing a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
396) Heap-based buffer overflow (CVE-ID: CVE-2026-69731)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the HID class driver when handling HID input locally. A local user can trigger the overflow locally to elevate privileges.
397) Heap-based buffer overflow (CVE-ID: CVE-2026-69732)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol when processing requests over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
Successful exploitation depends on environmental and system-configuration factors.
398) Use-after-free (CVE-ID: CVE-2026-69735)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain SYSTEM privileges.
The vulnerability exists due to use-after-free in Windows Broadcast DVR User Service when exploiting a race condition. A local user can win a race condition to gain SYSTEM privileges.
399) Integer overflow (CVE-ID: CVE-2026-69738)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Windows Biometric Service when processing data. A local user can trigger the overflow or wraparound to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
400) Use-after-free (CVE-ID: CVE-2026-69740)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Hello when it is used locally. A local user can exploit the use-after-free vulnerability locally to elevate privileges.
Successful exploitation could grant Virtual Trust Level 1 (VTL1) privileges.
401) Out-of-bounds read (CVE-ID: CVE-2026-69741)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Spaceport.sys when processing input locally. A local user can trigger the out-of-bounds read to disclose sensitive information.
The disclosed data may include heap memory from a privileged process running on the server.
402) NULL pointer dereference (CVE-ID: CVE-2026-69744)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in Windows Kerberos when handling network requests. A remote attacker can send a crafted network request to cause a denial of service.
403) Use-after-free (CVE-ID: CVE-2026-69757)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows TCP/IP when processing network traffic. A remote user can exploit the vulnerability over a network to elevate privileges.
User interaction is required. Successful exploitation requires a deep understanding of the system and depends on environmental and configuration factors.
404) Heap-based buffer overflow (CVE-ID: CVE-2026-69758)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Universal Disk Format File System Driver (UDFS) when handling UDFS data. A local user can supply specially crafted UDFS data to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
405) Out-of-bounds read (CVE-ID: CVE-2026-69760)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows Kerberos when handling network requests. A remote attacker can send a specially crafted network request to cause a denial of service.
406) Use-after-free (CVE-ID: CVE-2026-69761)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows TCP/IP when processing network traffic. A remote user can win a race condition to elevate privileges.
User interaction is required.
407) Stack-based buffer overflow (CVE-ID: CVE-2026-69762)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a stack-based buffer overflow in Windows Win32K when accessed over a network. A remote user can exploit the stack-based buffer overflow to elevate privileges.
User interaction is required, and successful exploitation can result in SYSTEM privileges.
408) Heap-based buffer overflow (CVE-ID: CVE-2026-69768)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows RNDIS when handling calls to arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
409) Heap-based buffer overflow (CVE-ID: CVE-2026-69769)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows HTTP Print Provider when processing calls to arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints to execute arbitrary code.
410) Use of uninitialized resource (CVE-ID: CVE-2026-69770)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to use of an uninitialized resource in Windows Spaceport.sys when processing local operations. A local user can exploit the vulnerability to disclose information.
Disclosed information may include uninitialized heap memory.
411) Link following (CVE-ID: CVE-2026-69771)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass access restrictions and access protected virtual hard disks in an attacker-controlled container.
The vulnerability exists due to improper link resolution before file access in Windows Container Manager Service when mapping virtual hard disks into containers. A local user can swap virtual hard disks through repeated exploitation attempts to bypass access restrictions and access protected virtual hard disks in an attacker-controlled container.
412) Heap-based buffer overflow (CVE-ID: CVE-2026-69772)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Network File System when processing a specially crafted file. A remote attacker can send a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file.
413) Heap-based buffer overflow (CVE-ID: CVE-2026-69773)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to gain SYSTEM privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing network input. A remote user can trigger the heap-based buffer overflow to gain SYSTEM privileges.
User interaction is required.
414) Use-after-free (CVE-ID: CVE-2026-69775)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to use-after-free in Windows DWM Core Library when winning a race condition over a network. A remote user can win a race condition to elevate privileges.
User interaction is required for exploitation. Successful exploitation can result in SYSTEM privileges.
415) Heap-based buffer overflow (CVE-ID: CVE-2026-69777)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows DHCP Client when processing DHCP traffic over an adjacent network. A remote user can send DHCP traffic that triggers the vulnerability to elevate privileges.
Successful exploitation can elevate privileges from Medium Integrity Level to Local Service.
416) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-69779)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a time-of-check time-of-use race condition in Windows Win32K when winning a race condition locally. A local user can win the race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
417) Memory leak (CVE-ID: CVE-2026-69781)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in Windows DHCP Client when handling DHCP traffic over an adjacent network. A remote attacker can send crafted DHCP traffic to cause a denial of service.
418) Race condition (CVE-ID: CVE-2026-69782)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to concurrent execution using a shared resource with improper synchronization (race condition) in DNS Server when calling arbitrary endpoints over a network. A remote attacker can win a race condition to execute arbitrary code.
419) Use-after-free (CVE-ID: CVE-2026-69784)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Hello when triggering a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation can provide Virtual Trust Level 1 (VTL1) privileges.
420) Untrusted search path (CVE-ID: CVE-2026-69785)
CWE-ID: CWE-426 - Untrusted Search Path
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an untrusted search path in Windows Smart Card when loading resources locally. A local user can exploit the untrusted search path to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
421) Heap-based buffer overflow (CVE-ID: CVE-2026-69786)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Text Shaping when processing a specially crafted file. A remote attacker can send a specially crafted file to execute arbitrary code.
Successful exploitation may depend on the environment, system configuration, and additional security measures.
422) Heap-based buffer overflow (CVE-ID: CVE-2026-69787)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing locally supplied input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
423) Heap-based buffer overflow (CVE-ID: CVE-2026-69790)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Credential Providers when handling credential provider operations. A local user can trigger the overflow to elevate privileges.
424) Use-after-free (CVE-ID: CVE-2026-69791)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Device Association Service when winning a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
425) Race condition (CVE-ID: CVE-2026-69792)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass the Windows Lock Screen security feature.
The vulnerability exists due to a race condition in Windows Win32K when concurrently accessing a shared resource. A local user can win a race condition to bypass the Windows Lock Screen security feature.
426) Improper Validation of Consistency within Input (CVE-ID: CVE-2026-69793)
CWE-ID: CWE-1288 - Improper Validation of Consistency within Input
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass network access controls.
The vulnerability exists due to improper validation of consistency within input in Windows TCP/IP when handling network input. A remote attacker can send network traffic to bypass network access controls.
The bypass affects controls that restrict which remote IPv6 traffic an application accepts.
427) Buffer over-read (CVE-ID: CVE-2026-69794)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to a buffer over-read in Windows Encrypting File System (EFS) when handling EFS operations. A local user can trigger the buffer over-read to disclose sensitive information.
Successful exploitation could expose heap memory from a privileged process running on the server.
428) Race condition (CVE-ID: CVE-2026-69799)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to concurrent execution using a shared resource with improper synchronization (race condition) in Windows Hello when concurrent execution accesses a shared resource. A local user can win a race condition to escalate privileges.
The elevated privileges are at Virtual Trust Level 1 (VTL1).
429) Heap-based buffer overflow (CVE-ID: CVE-2026-69801)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Audio Service when processing input. A local user can exploit the heap-based buffer overflow to escalate privileges.
Successful exploitation can result in SYSTEM privileges.
430) Out-of-bounds read (CVE-ID: CVE-2026-69803)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when handling network requests. A remote attacker can send a specially crafted network request to disclose sensitive information.
Successfully exploiting the vulnerability could expose heap memory from a privileged process running on the server.
431) Path traversal (CVE-ID: CVE-2026-69807)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in Windows PowerShell when handling a pathname over a network. A remote user can exploit the path traversal flaw to elevate privileges.
User interaction is required.
432) Out-of-bounds read (CVE-ID: CVE-2026-69808)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows Win32K when accessing the component locally. A local user can trigger the out-of-bounds read to disclose information.
Disclosed information may include unauthorized access to file system path information.
433) Memory leak (CVE-ID: CVE-2026-69809)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in Active Directory Domain Services when processing network requests. A remote attacker can send network requests to cause a denial of service.
434) Use-after-free (CVE-ID: CVE-2026-69813)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows DNS when handling calls to arbitrary endpoints. A remote attacker can call arbitrary endpoints to execute arbitrary code.
Successful exploitation requires winning a race condition.
435) Use-after-free (CVE-ID: CVE-2026-69814)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Credential Providers when handling credential provider operations. A local user can exploit a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
436) Use-after-free (CVE-ID: CVE-2026-69816)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Accounts Control when winning a race condition. A local user can win a race condition to escalate privileges.
Successful exploitation can result in SYSTEM privileges.
437) Use-after-free (CVE-ID: CVE-2026-69817)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows Bluetooth Port Driver when a race condition is won. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
438) Use-after-free (CVE-ID: CVE-2026-69818)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Win32K when winning a race condition. A local user can exploit the race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
439) Out-of-bounds write (CVE-ID: CVE-2026-69819)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds write in RPC Runtime when handling calls to arbitrary endpoints. A remote attacker can call arbitrary endpoints over a network to execute arbitrary code.
440) Heap-based buffer overflow (CVE-ID: CVE-2026-69820)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Hello when exploited locally. A local privileged user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could provide Virtual Trust Level 1 (VTL1) privileges.
441) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-69821)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to improper encoding or escaping of output in Active Directory Certificate Services (AD CS) when processing output. A local user can exploit the improperly encoded or escaped output to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
442) Numeric Truncation Error (CVE-ID: CVE-2026-69822)
CWE-ID: CWE-197 - Numeric Truncation Error
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to numeric truncation in Windows Kerberos when processing Kerberos data. A local user can exploit the numeric truncation error to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
443) Integer underflow (CVE-ID: CVE-2026-69824)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer underflow in Microsoft Standard XPS when processing calls to arbitrary endpoints. A remote attacker can call arbitrary endpoints to execute arbitrary code.
444) Heap-based buffer overflow (CVE-ID: CVE-2026-69826)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing network input. A remote user can send network input to elevate privileges.
User interaction is required for exploitation. Successful exploitation could grant SYSTEM privileges.
445) Race condition (CVE-ID: CVE-2026-69827)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a race condition in DNS Server when processing calls to arbitrary endpoints. A remote attacker can call arbitrary endpoints to execute arbitrary code.
Successful exploitation requires winning a race condition.
446) Heap-based buffer overflow (CVE-ID: CVE-2026-69829)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Shell when handling calls to arbitrary endpoints over a network. A remote attacker can call arbitrary endpoints over a network to execute arbitrary code.
447) Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-ID: CVE-2026-69832)
CWE-ID: CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive system information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Windows Win32K when exploiting Win32K locally. A local user can win a race condition to disclose sensitive system information.
448) Use-after-free (CVE-ID: CVE-2026-69834)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows ALPC when processing local ALPC operations. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
449) Use-after-free (CVE-ID: CVE-2026-69838)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Print Spooler Components when attempting to exploit a race condition locally. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
450) Uncaught Exception (CVE-ID: CVE-2026-69839)
CWE-ID: CWE-248 - Uncaught Exception
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an uncaught exception in the Windows iSCSI Target Service when handling network requests. A remote user can send a specially crafted network request to cause a denial of service.
451) Heap-based buffer overflow (CVE-ID: CVE-2026-69841)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Encrypting File System (EFS) when processing EFS operations. A local user can exploit the buffer overflow to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
452) Out-of-bounds read (CVE-ID: CVE-2026-69844)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows Win32K when it is accessed locally. A local user can exploit the out-of-bounds read to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
453) Heap-based buffer overflow (CVE-ID: CVE-2026-69845)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows DHCP Server when calling arbitrary endpoints. A remote attacker can call arbitrary endpoints to execute arbitrary code.
454) Integer overflow (CVE-ID: CVE-2026-69846)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Windows Secure Kernel Mode when processing a specially crafted Code Integrity policy. A local privileged user can submit a specially crafted Code Integrity policy to elevate privileges.
Successful exploitation can provide Virtual Trust Level 1 (VTL1) privileges and allow code execution in VTL1. Exploitation requires pre-existing kernel-level access.
455) Heap-based buffer overflow (CVE-ID: CVE-2026-69847)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows DHCP Server when handling specially crafted requests over an adjacent network. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
456) Heap-based buffer overflow (CVE-ID: CVE-2026-69852)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) when processing network input. A remote user can exploit the vulnerability to execute arbitrary code.
Successful exploitation requires a deep understanding of the system and depends on environmental and system-configuration factors, as well as the presence of additional security measures.
457) Use of uninitialized resource (CVE-ID: CVE-2026-69853)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to use of an uninitialized resource in Windows Win32K when winning a race condition locally. A local user can win a race condition to disclose information.
Successful exploitation can disclose uninitialized heap memory.
458) Use-after-free (CVE-ID: CVE-2026-69858)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows DNS when processing a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
Successful exploitation requires winning a race condition.
459) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-69859)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a time-of-check time-of-use race condition in the Windows USB Audio Class driver (usbaudio.sys) when handling local operations. A local user can exploit the race condition to escalate privileges.
Successful exploitation depends on a combination of factors that may include the environment, system configuration, and additional security measures.
460) Heap-based buffer overflow (CVE-ID: CVE-2026-69860)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Imaging Component when processing a specially crafted file. A remote attacker can send a specially crafted file to a user to execute arbitrary code.
User interaction is required to open the specially crafted file.
461) Out-of-bounds read (CVE-ID: CVE-2026-69862)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the Windows Wireless Wide Area Network Service when processing locally supplied input. A local user can trigger the out-of-bounds read to disclose sensitive information.
Disclosed information may include uninitialized heap memory.
462) Use-after-free (CVE-ID: CVE-2026-69864)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Hello when winning a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation could grant Virtual Trust Level 1 (VTL1) privileges.
463) Use-after-free (CVE-ID: CVE-2026-69866)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Device Association Service when a race condition is won. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
464) Untrusted Pointer Dereference (CVE-ID: CVE-2026-69874)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to untrusted pointer dereference in Windows ALPC when processing ALPC requests. A local privileged user can trigger the untrusted pointer dereference to elevate privileges.
Successful exploitation could grant Virtual Trust Level 1 (VTL1) privileges.
465) Heap-based buffer overflow (CVE-ID: CVE-2026-69875)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to gain SYSTEM privileges.
The vulnerability exists due to heap-based buffer overflow in Windows NTFS when processing NTFS data over a network. A remote user can trigger the heap-based buffer overflow to gain SYSTEM privileges.
User interaction is required.
466) Use-after-free (CVE-ID: CVE-2026-69876)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows DHCP Server when handling a specially crafted request over an adjacent network. A remote user can send a specially crafted request to execute arbitrary code.
467) Heap-based buffer overflow (CVE-ID: CVE-2026-69878)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows DHCP Server when accessing the server locally. A local privileged user can exploit the heap-based buffer overflow to execute arbitrary code.
Successful exploitation requires a deep understanding of the system and depends on environmental and system-configuration factors.
468) NULL pointer dereference (CVE-ID: CVE-2026-69881)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in Windows IKE Extension when handling network requests. A remote attacker can send a network request to cause a denial of service.
469) Use-after-free (CVE-ID: CVE-2026-69889)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Bluetooth Service when winning a race condition. A local user can exploit the race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
470) Use-after-free (CVE-ID: CVE-2026-69890)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Virtual Trusted Platform Module when exploiting a race condition. A local privileged user can win a race condition to escalate privileges.
The elevated privileges are at Virtual Trust Level 1 (VTL1).
471) Use-after-free (CVE-ID: CVE-2026-69891)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Media when using Windows Media. A local user can trigger the use-after-free to elevate privileges.
Successful exploitation requires winning a race condition and can grant SYSTEM privileges.
472) Out-of-bounds read (CVE-ID: CVE-2026-69895)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in Windows Spaceport.sys when accessing the driver locally. A local user can trigger the out-of-bounds read to disclose sensitive information.
Disclosed information may include heap memory from a privileged process running on the server.
473) Use-after-free (CVE-ID: CVE-2026-69896)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Error Reporting when handling local operations. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
474) Untrusted Pointer Dereference (CVE-ID: CVE-2026-69900)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to untrusted pointer dereference in the Kernel Streaming WOW Thunk Service Driver when processing an untrusted pointer. A local user can provide a crafted pointer to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
475) Heap-based buffer overflow (CVE-ID: CVE-2026-69906)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Secure Kernel Mode when processing local input. A local privileged user can exploit the overflow to elevate privileges.
Successful exploitation could allow code execution in the kernel.
476) Improper Handling of Insufficient Permissions or Privileges (CVE-ID: CVE-2026-69907)
CWE-ID: CWE-280 - Improper Handling of Insufficient Permissions or Privileges
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper handling of insufficient permissions or privileges in Windows Enterprise App Management when handling insufficient permissions or privileges locally. A local user can exploit the vulnerability to escalate privileges.
Successful exploitation can grant SYSTEM privileges.
477) Stack-based buffer overflow (CVE-ID: CVE-2026-69910)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Windows Hyper-V when handling specially crafted file operation requests. A remote attacker can send specially crafted file operation requests from a guest VM to execute arbitrary code.
478) Use-after-free (CVE-ID: CVE-2026-69911)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Microsoft Windows Search Component when winning a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
479) Heap-based buffer overflow (CVE-ID: CVE-2026-69921)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Print Spooler Components when exploited locally. A local user can trigger the heap-based buffer overflow to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
480) Out-of-bounds read (CVE-ID: CVE-2026-69929)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when handling network requests. A remote attacker can send a specially crafted network request to disclose sensitive information.
Successful exploitation could allow viewing heap memory from a privileged process running on the server.
481) Out-of-bounds read (CVE-ID: CVE-2026-69930)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when handling network requests. A remote attacker can send a specially crafted network request to disclose sensitive information.
Successfully exploiting the vulnerability could expose heap memory from a privileged process running on the server.
482) Use-after-free (CVE-ID: CVE-2026-69989)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in DNS Server when calling arbitrary endpoints over the network. A remote attacker can call arbitrary endpoints over the network to execute arbitrary code.
Successful exploitation requires winning a race condition.
483) Windows hard link (CVE-ID: CVE-2026-70019)
CWE-ID: CWE-65 - Windows hard link
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read files from the file system.
The vulnerability exists due to a Windows hard link in Windows Compressed Folder when processing a compressed folder containing a Windows hard link. A remote attacker can use a Windows hard link in a compressed folder to read files from the file system.
User interaction is required.
484) Memory leak (CVE-ID: CVE-2026-70065)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in Windows DHCP Server when handling network requests. A remote attacker can send network requests to the DHCP Server to cause a denial of service.
485) Race condition (CVE-ID: CVE-2026-70091)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to concurrent execution using a shared resource with improper synchronization (race condition) in Windows DNS when processing network activity. A remote attacker can trigger concurrent execution using a shared resource to cause a denial of service.
486) Out-of-bounds read (CVE-ID: CVE-2026-70124)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when processing network traffic. A remote attacker can exploit the out-of-bounds read to disclose sensitive information.
487) Out-of-bounds read (CVE-ID: CVE-2026-70145)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the Microsoft Windows Search Component when processing locally supplied input. A local user can trigger the out-of-bounds read to disclose sensitive information.
Disclosed information may include heap memory from a privileged process running on the server.
488) Heap-based buffer overflow (CVE-ID: CVE-2026-70203)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Media Player when processing a specially crafted media file. A remote attacker can convince a user to open a specially crafted media file to execute arbitrary code.
489) Incorrect authorization (CVE-ID: CVE-2026-70283)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to incorrect authorization in Windows Win32K when processing a specially crafted keyboard layout file. A local user can place a specially crafted keyboard layout file on the affected system and chain it with an additional vulnerability to elevate privileges.
User interaction is not required.
490) Heap-based buffer overflow (CVE-ID: CVE-2026-70289)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Win32 Kernel Subsystem when processing input locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
491) Use of uninitialized resource (CVE-ID: CVE-2026-70290)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to use of an uninitialized resource in the Windows Win32 Kernel Subsystem when used locally. A local user can exploit the vulnerability to disclose information.
The exposed data is limited to one byte of kernel memory.
492) Out-of-bounds write (CVE-ID: CVE-2026-70296)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds write in Windows Imaging Component when generating thumbnails or previews for crafted RAW image files. A remote attacker can provide a specially crafted RAW image file to execute arbitrary code.
493) Use-after-free (CVE-ID: CVE-2026-70342)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to use-after-free in the Windows Ancillary Function Driver for WinSock when handling concurrent, specially crafted networking requests. A remote attacker can send concurrent, specially crafted networking requests to gain SYSTEM privileges.
Successful exploitation requires winning a race condition.
494) Double free (CVE-ID: CVE-2026-70562)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a double free in Windows Audio Service when winning a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
495) Link following (CVE-ID: CVE-2026-70563)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform spoofing.
The vulnerability exists due to improper link resolution before file access (\'link following\') in Windows Shell when resolving a specially crafted shortcut. A remote attacker can convince a user to access a location containing the shortcut to perform spoofing.
496) Heap-based buffer overflow (CVE-ID: CVE-2026-70564)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Print Spooler Components when processing local input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
497) Use-after-free (CVE-ID: CVE-2026-70565)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in the Windows AF_UNIX Socket Provider when handling local socket operations. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
498) Double free (CVE-ID: CVE-2026-70567)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a double free in the Windows Display Enhancement Service when exploited locally. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
499) Heap-based buffer overflow (CVE-ID: CVE-2026-70568)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Defender Firewall Service when handling local input. A local user can exploit a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
500) Out-of-bounds read (CVE-ID: CVE-2026-70569)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to an out-of-bounds read in Windows Spaceport.sys when processing locally supplied input. A local user can exploit the out-of-bounds read to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
501) Use-after-free (CVE-ID: CVE-2026-70570)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Routing and Remote Access Service (RRAS) when winning a race condition. A remote attacker can win a race condition to execute arbitrary code.
502) Integer overflow (CVE-ID: CVE-2026-70572)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges to SYSTEM privileges.
The vulnerability exists due to integer overflow or wraparound in Windows Biometric Service when handling requests. A local user can exploit the integer overflow to elevate privileges to SYSTEM privileges.
503) Heap-based buffer overflow (CVE-ID: CVE-2026-70573)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when interacting with the service locally. A local user can trigger the buffer overflow to elevate privileges.
Successful exploitation requires winning a race condition.
504) Out-of-bounds read (CVE-ID: CVE-2026-70574)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in the Virtual Hard Disk (VHD) Miniport Driver when exploited locally. A local user can exploit the out-of-bounds read to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
505) NULL pointer dereference (CVE-ID: CVE-2026-70575)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in Windows Schannel when processing network input. A remote user can trigger the null pointer dereference to cause a denial of service.
506) Use-after-free (CVE-ID: CVE-2026-70577)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Modern Device Management (MDM) when winning a race condition locally. A local user can win a race condition to elevate privileges.
507) Heap-based buffer overflow (CVE-ID: CVE-2026-70578)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Credential Guard when winning a race condition. A local user can win a race condition to escalate privileges.
Successful exploitation could result in SYSTEM privileges.
508) Out-of-bounds read (CVE-ID: CVE-2026-70579)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Windows Mobile Broadband when processing network requests. A remote attacker can send network requests to disclose sensitive information.
Successful exploitation can expose heap memory from a privileged process running on the server.
509) Integer overflow (CVE-ID: CVE-2026-70581)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Windows Biometric Service when processing data. A local user can trigger the integer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
510) Race condition (CVE-ID: CVE-2026-70582)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to concurrent execution using shared resource with improper synchronization (\'race condition\') in Windows Management Instrumentation when executing concurrently using shared resources. A local privileged user can win a race condition to elevate privileges.
511) Heap-based buffer overflow (CVE-ID: CVE-2026-70583)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain SYSTEM privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Core Messaging when it is accessed locally. A local user can exploit the vulnerability to gain SYSTEM privileges.
512) Type Confusion (CVE-ID: CVE-2026-70584)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to access of a resource using an incompatible type (type confusion) in Windows Core Messaging when processing local input. A local user can exploit the type confusion to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
513) Use-after-free (CVE-ID: CVE-2026-70585)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute code.
The vulnerability exists due to use-after-free in the Windows Services for NFS ONCRPC XDR Driver when exploiting the driver. A local user can trigger the use-after-free condition to execute code.
Successful exploitation requires winning a race condition.
514) Heap-based buffer overflow (CVE-ID: CVE-2026-70586)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Paint when processing a specially crafted file. A remote attacker can send a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file.
515) Improper Null Termination (CVE-ID: CVE-2026-70587)
CWE-ID: CWE-170 - Improper Null Termination
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper null termination in Windows Remote Desktop Protocol when handling network requests. A remote attacker can send network requests to disclose sensitive information.
Exposed data may include heap memory from a privileged process running on the server.
516) Heap-based buffer overflow (CVE-ID: CVE-2026-71329)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when a specially crafted USB device is inserted. An attacker with physical access can insert a specially crafted USB device to execute arbitrary code.
The issue can also be exploited by mounting a specially crafted virtual hard drive.
517) Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-ID: CVE-2026-71330)
CWE-ID: CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in the Windows Services for NFS ONCRPC XDR Driver when handling network requests. A remote attacker can send a specially crafted network request to disclose sensitive information.
Successful exploitation can disclose small portions of uninitialized kernel stack memory.
518) Use-after-free (CVE-ID: CVE-2026-71332)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Secure Socket Tunneling Protocol (SSTP) when handling SSTP connections. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
519) Use-after-free (CVE-ID: CVE-2026-71333)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Remote Access Connection Manager when exploiting a race condition locally. A local user can exploit the race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
520) Heap-based buffer overflow (CVE-ID: CVE-2026-71334)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows NFS Portmapper when handling input. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
521) Integer overflow (CVE-ID: CVE-2026-71336)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to integer overflow or wraparound in Windows Work Folder Service when handling specially crafted network requests. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
522) Stack-based buffer overflow (CVE-ID: CVE-2026-71337)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a stack-based buffer overflow in Windows Storage Management Provider when used locally. A local user can trigger the overflow to escalate privileges.
The elevation path is from Medium Integrity Level to Local Service.
523) Double free (CVE-ID: CVE-2026-71338)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to gain SYSTEM privileges.
The vulnerability exists due to a double free in Windows Failover Cluster when winning a race condition. A local privileged user can exploit the double free to gain SYSTEM privileges.
524) Heap-based buffer overflow (CVE-ID: CVE-2026-71339)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Installer when used locally. A local privileged user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
525) Use-after-free (CVE-ID: CVE-2026-71340)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows File History Service when winning a race condition. A local user can win a race condition to elevate privileges.
526) Out-of-bounds read (CVE-ID: CVE-2026-71341)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the Windows Partition Management Driver when accessing the driver locally. A local user can trigger an out-of-bounds read to disclose sensitive information.
The issue permits unintentional read access to kernel-space memory contents from a user-mode process.
527) Use-after-free (CVE-ID: CVE-2026-71342)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Remote Access Connection Manager when winning a race condition. A local user can win a race condition to elevate privileges.
528) Heap-based buffer overflow (CVE-ID: CVE-2026-71343)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code locally.
The vulnerability exists due to a heap-based buffer overflow in Windows Remote Access Connection Manager when executing code on the local machine. A local user can trigger the vulnerability to execute arbitrary code locally.
529) Out-of-bounds write (CVE-ID: CVE-2026-71345)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute code.
The vulnerability exists due to an out-of-bounds write in Windows Spaceport.sys when executing code on the local machine. A local user can execute code on the local machine to execute code.
No administrative or other elevated privileges are required.
530) Heap-based buffer overflow (CVE-ID: CVE-2026-71348)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Spaceport.sys when handling a malicious USB drive. An attacker with physical access can plug in a malicious USB drive to execute arbitrary code.
531) Heap-based buffer overflow (CVE-ID: CVE-2026-71349)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Spaceport.sys when physical access to the victim\'s machine is available. An attacker with physical access can exploit the heap-based buffer overflow to execute arbitrary code.
532) Heap-based buffer overflow (CVE-ID: CVE-2026-71350)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Spaceport.sys when handling physical attack input. An attacker with physical access can exploit the heap-based buffer overflow to execute arbitrary code.
533) Double free (CVE-ID: CVE-2026-71351)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a double free in Windows Routing and Remote Access Service (RRAS) when winning a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation can elevate privileges from Medium Integrity Level to Local Service.
534) Integer underflow (CVE-ID: CVE-2026-71352)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager when handling specially crafted network requests. A remote user can send a specially crafted request to execute arbitrary code.
User interaction is not required.
535) Double free (CVE-ID: CVE-2026-71353)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a double free in Windows Routing and Remote Access Service (RRAS) when attempting local exploitation. A local user can win a race condition to elevate privileges.
Successful exploitation can elevate privileges from Medium Integrity Level to Local Service.
536) Use-after-free (CVE-ID: CVE-2026-72926)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Internet Connection Sharing (ICS) when handling ICS operations. A local user can win a race condition to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
537) Heap-based buffer overflow (CVE-ID: CVE-2026-72927)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to gain SYSTEM privileges.
The vulnerability exists due to a heap-based buffer overflow in Winsock when processing locally supplied input. A local privileged user can trigger the heap-based buffer overflow to gain SYSTEM privileges.
538) Use-after-free (CVE-ID: CVE-2026-72928)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows DNS when handling network requests. A remote user can win a race condition to execute arbitrary code.
Successful exploitation requires winning a race condition.
539) Improper validation of integrity check value (CVE-ID: CVE-2026-72929)
CWE-ID: CWE-354 - Improper Validation of Integrity Check Value
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to improper validation of an integrity check value in Windows Installer when processing integrity check values. A local user can exploit the improper validation to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
540) Use-after-free (CVE-ID: CVE-2026-72930)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Secure Socket Tunneling Protocol (SSTP) when handling SSTP connections. A local user can trigger the use-after-free condition to execute arbitrary code.
Successful exploitation requires winning a race condition.
541) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-72931)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) when handling SSTP operations locally. A local user can exploit the vulnerability locally to cause a denial of service.
542) Buffer over-read (CVE-ID: CVE-2026-72932)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a buffer over-read in Windows Message Queuing Queue Manager when processing network requests. A remote attacker can send a specially crafted network request to disclose sensitive information.
Disclosed information may include heap memory from a privileged process running on the server.
543) Heap-based buffer overflow (CVE-ID: CVE-2026-72933)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Microsoft WDAC OLE DB provider for SQL when processing a malicious server response. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
User interaction is required.
544) Out-of-bounds read (CVE-ID: CVE-2026-72935)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows NTFS when accessing the Windows NTFS file system. A local privileged user can trigger the out-of-bounds read to elevate privileges.
545) Use-after-free (CVE-ID: CVE-2026-72936)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows SMB Client when processing specially crafted packets. A remote attacker can send a specially crafted packet to an affected service to execute arbitrary code.
Successful exploitation requires winning a race condition.
546) Out-of-bounds read (CVE-ID: CVE-2026-72937)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the Storage Port Driver when processing local requests. A local user can trigger the out-of-bounds read to disclose sensitive information.
Disclosed information may include kernel memory contents accessible from a user-mode process.
547) NULL pointer dereference (CVE-ID: CVE-2026-72939)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in Windows Routing and Remote Access Service (RRAS) when handling network requests. A remote user can trigger the null pointer dereference to cause a denial of service.
548) Heap-based buffer overflow (CVE-ID: CVE-2026-72940)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Schannel when processing a response from a malicious server. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
549) Heap-based buffer overflow (CVE-ID: CVE-2026-72941)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing locally supplied input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
550) Out-of-bounds read (CVE-ID: CVE-2026-72942)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows Spaceport.sys when accessed over a network. A remote attacker can initiate exploitation over a network to disclose information.
User interaction is required.
551) Use-after-free (CVE-ID: CVE-2026-72943)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Deployment Services when handling network requests. A remote user can interact with the service over a network to execute arbitrary code.
Successful exploitation requires winning a race condition.
552) Heap-based buffer overflow (CVE-ID: CVE-2026-72944)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Fax Service when processing locally supplied input. A local user can exploit the buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
553) Use of uninitialized resource (CVE-ID: CVE-2026-72945)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use of an uninitialized resource in Windows Task Scheduler when handling local operations. A local user can exploit the vulnerability to disclose sensitive information.
The disclosed data may include uninitialized heap memory from a privileged process.
554) Heap-based buffer overflow (CVE-ID: CVE-2026-72946)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Storage Port Driver when processing input locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
555) Integer underflow (CVE-ID: CVE-2026-72947)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to integer underflow in Windows File History Service when accessing the service locally. A local privileged user can exploit the integer underflow to elevate privileges.
Successful exploitation requires winning a race condition.
556) Relative Path Traversal (CVE-ID: CVE-2026-72948)
CWE-ID: CWE-23 - Relative Path Traversal
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to escalate privileges.
The vulnerability exists due to relative path traversal in Windows DNS when handling relative paths. A local privileged user can use crafted relative paths to escalate privileges.
Successful exploitation can grant SYSTEM privileges.
557) NULL pointer dereference (CVE-ID: CVE-2026-72949)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in the Windows SMB Server Network Transport Driver (srvnet.sys) when handling network requests. A remote attacker can send a network request to cause a denial of service.
558) Heap-based buffer overflow (CVE-ID: CVE-2026-72950)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code on the server.
The vulnerability exists due to heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) when handling a specially crafted request. A remote user can send a specially crafted request to execute arbitrary code on the server.
User interaction is not required.
559) Out-of-bounds read (CVE-ID: CVE-2026-72952)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute code.
The vulnerability exists due to an out-of-bounds read in Windows Spaceport.sys when handling input locally. A local user can trigger the out-of-bounds read to execute code.
Successful exploitation requires winning a race condition.
560) Heap-based buffer overflow (CVE-ID: CVE-2026-72953)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows USB Driver when invoked locally. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
561) Use-after-free (CVE-ID: CVE-2026-72954)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Deployment Services when handling network input. A remote user can win a race condition to execute arbitrary code.
562) Heap-based buffer overflow (CVE-ID: CVE-2026-72957)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Deployment Services when executing code locally. A local user can trigger the vulnerability to execute arbitrary code.
563) Double free (CVE-ID: CVE-2026-72958)
CWE-ID: CWE-415 - Double Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to double free in Windows Credential Guard when triggering a double-free condition locally. A local privileged user can exploit the double-free condition to elevate privileges.
Successful exploitation can grant Virtual Trust Level 1 (VTL1) privileges.
564) Heap-based buffer overflow (CVE-ID: CVE-2026-72959)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code on the server.
The vulnerability exists due to a heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) when handling a specially crafted request. A remote user can send a specially crafted request to execute arbitrary code on the server.
User interaction is not required.
565) Heap-based buffer overflow (CVE-ID: CVE-2026-72960)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Media Player when handling a specially crafted file. A remote attacker can send a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file.
566) Out-of-bounds read (CVE-ID: CVE-2026-72961)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows Hyper-V when processing specially crafted virtual TPM state data. A local privileged user can supply specially crafted virtual TPM state data to a virtual machine to elevate privileges.
Successful exploitation can provide Virtual Trust Level 1 (VTL1) privileges across a security boundary.
567) Heap-based buffer overflow (CVE-ID: CVE-2026-72962)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows USB Video Driver when handling specially crafted requests to the affected USB video component on the local system. A local privileged user can send specially crafted requests to elevate privileges.
Successful exploitation can grant Virtual Trust Level 1 (VTL1) privileges.
568) Use-after-free (CVE-ID: CVE-2026-72963)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Modern Execution Server when processing local operations. A local user can win a race condition to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
569) Missing Authentication for Critical Function (CVE-ID: CVE-2026-72964)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make unauthorized modifications to protected system data.
The vulnerability exists due to missing authentication for a critical function in Windows Internet Connection Sharing (ICS) when invoking the critical function locally. A local user can invoke the critical function to make unauthorized modifications to protected system data.
570) Use-after-free (CVE-ID: CVE-2026-72965)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows WebClient Service when handling locally initiated operations. A local user can trigger the use-after-free condition to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
571) Missing Authorization (CVE-ID: CVE-2026-72966)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to modify protected system data.
The vulnerability exists due to missing authorization in Windows Remote Access Connection Manager when performing local operations. A local user can exploit the missing authorization to modify protected system data.
No administrative or other elevated privileges are required.
572) Heap-based buffer overflow (CVE-ID: CVE-2026-72967)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Network Connection Broker when processing input. A local user can exploit the flaw to elevate privileges.
573) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-72978)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) when processing network requests. A remote attacker can send network requests to cause a denial of service.
574) Use-after-free (CVE-ID: CVE-2026-72979)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows DHCP Server when processing a specially crafted packet. A remote attacker can send a specially crafted packet to an affected service over the network to execute arbitrary code.
User interaction is not required.
575) Insecure DLL loading (CVE-ID: CVE-2026-72980)
CWE-ID: CWE-427 - Uncontrolled Search Path Element
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to bypass the Windows Hello security feature.
The vulnerability exists due to an uncontrolled search path element in Windows Hello when resolving locally accessible search paths. A local privileged user can exploit the uncontrolled search path element to bypass the Windows Hello security feature.
576) Use-after-free (CVE-ID: CVE-2026-72981)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in IP Helper when processing specially crafted packets sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
Successful exploitation requires winning a race condition.
577) Stack-based buffer overflow (CVE-ID: CVE-2026-72982)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Windows Netlogon when processing a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
No user interaction is required.
578) Use-after-free (CVE-ID: CVE-2026-72983)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Internet Connection Sharing (ICS) when processing a specially crafted network packet. A remote attacker can send a specially crafted packet to the affected service to execute arbitrary code.
No user interaction is required.
579) Heap-based buffer overflow (CVE-ID: CVE-2026-72985)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Volume Shadow Copy when performing a physical attack. An attacker with physical access can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
580) Heap-based buffer overflow (CVE-ID: CVE-2026-72986)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Graphic Fonts when processing a specially crafted file. A remote attacker can send a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file.
581) Use-after-free (CVE-ID: CVE-2026-72987)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows DNS when handling a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
Successful exploitation requires a specific condition and depends on environmental and system-configuration factors.
582) Heap-based buffer overflow (CVE-ID: CVE-2026-72988)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges to SYSTEM privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when handling input from a local user. A local user can trigger the overflow to elevate privileges to SYSTEM privileges.
583) Use of uninitialized resource (CVE-ID: CVE-2026-72989)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of an uninitialized resource in Windows Failover Cluster when accessed over a network. A remote attacker can access the vulnerable component over a network to disclose sensitive information.
Disclosed information may include uninitialized stack memory.
584) Heap-based buffer overflow (CVE-ID: CVE-2026-72990)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing locally supplied input. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
585) Heap-based buffer overflow (CVE-ID: CVE-2026-72991)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when interacting with the service locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
586) Heap-based buffer overflow (CVE-ID: CVE-2026-72992)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when the service is used locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
587) Heap-based buffer overflow (CVE-ID: CVE-2026-72993)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when exploited locally. A local user can exploit the vulnerability locally to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
588) Heap-based buffer overflow (CVE-ID: CVE-2026-72994)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Biometric Service when handling locally initiated operations. A local user can trigger the overflow to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
589) Heap-based buffer overflow (CVE-ID: CVE-2026-72995)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing local input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
590) Heap-based buffer overflow (CVE-ID: CVE-2026-72996)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
591) Heap-based buffer overflow (CVE-ID: CVE-2026-72997)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing locally supplied input. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
592) Out-of-bounds read (CVE-ID: CVE-2026-72999)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to elevate privileges.
The vulnerability exists due to an out-of-bounds read in the Windows USB Hub Driver when processing a malicious USB device. An attacker with physical access can plug in a malicious USB device to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
593) Heap-based buffer overflow (CVE-ID: CVE-2026-73000)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
594) Heap-based buffer overflow (CVE-ID: CVE-2026-73001)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing local input. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
595) Integer overflow (CVE-ID: CVE-2026-73002)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Windows Biometric Service when used locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
596) Use-after-free (CVE-ID: CVE-2026-73003)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Modern Device Management (MDM) when it is used locally. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
597) Missing Authentication for Critical Function (CVE-ID: CVE-2026-73004)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to modify protected system data.
The vulnerability exists due to missing authentication for a critical function in Windows Autopilot when performing local operations. A local user can perform tampering to modify protected system data.
The modifications can alter system state or configuration beyond normal privileges.
598) Use-after-free (CVE-ID: CVE-2026-73005)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Authentication Methods when handling authentication operations. A local user can win a race condition to escalate privileges.
Successful exploitation can result in SYSTEM privileges.
599) Stack-based buffer overflow (CVE-ID: CVE-2026-73006)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in the Microsoft Graphics Component when a user opens a specially crafted file. A remote attacker can provide a specially crafted file to a user to execute arbitrary code.
600) Heap-based buffer overflow (CVE-ID: CVE-2026-73007)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when it is accessed locally. A local user can trigger the overflow to elevate privileges.
601) Exposure of Private Information ('Privacy Violation') (CVE-ID: CVE-2026-73008)
CWE-ID: CWE-359 - Exposure of Private Information ('Privacy Violation')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of private personal information to an unauthorized actor in Windows Biometric Service when accessing the service locally. A local user can access sensitive user data to disclose sensitive information.
602) Use-after-free (CVE-ID: CVE-2026-73009)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Secure Socket Tunneling Protocol (SSTP) when processing a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
No authentication or user interaction is required.
603) Use-after-free (CVE-ID: CVE-2026-73010)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Failover Cluster when processing a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
604) Heap-based buffer overflow (CVE-ID: CVE-2026-73011)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when exploited locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
605) Heap-based buffer overflow (CVE-ID: CVE-2026-73012)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Management Services when processing specially crafted requests sent to an affected service over the network. A remote user can send a specially crafted request to elevate privileges.
Successful exploitation can allow code execution on the target system.
606) Heap-based buffer overflow (CVE-ID: CVE-2026-73013)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Imaging Component when processing a specially crafted file. A remote attacker can provide a specially crafted file to execute arbitrary code.
User interaction is required to open the crafted file.
607) Missing Authorization (CVE-ID: CVE-2026-73014)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain SYSTEM privileges.
The vulnerability exists due to missing authorization in Data Sharing Service Client when accessing the client locally. A local user can access the client locally to gain SYSTEM privileges.
608) Heap-based buffer overflow (CVE-ID: CVE-2026-73015)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to heap-based buffer overflow in Windows Biometric Service when processing locally supplied input. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
609) Heap-based buffer overflow (CVE-ID: CVE-2026-73016)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Graphics Component when a user opens a specially crafted file. A remote attacker can send a specially crafted file to execute code.
610) Heap-based buffer overflow (CVE-ID: CVE-2026-73017)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Windows Graphics Kernel when processing graphics operations. A local privileged user can trigger a specific condition to execute arbitrary code.
Successful exploitation requires a deep understanding of the system and the ability to manipulate its components.
611) Heap-based buffer overflow (CVE-ID: CVE-2026-73018)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Graphic Fonts when processing a specially crafted file. A remote attacker can send a specially crafted file to execute arbitrary code.
User interaction is required to open the crafted file.
612) Improper Resolution of Path Equivalence (CVE-ID: CVE-2026-73019)
CWE-ID: CWE-41 - Improper Resolution of Path Equivalence
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security feature.
The vulnerability exists due to improper resolution of path equivalence in Windows URL Moniker when handling a path over a network. A remote attacker can use a path with an equivalent representation to bypass a security feature.
User interaction is required.
613) Heap-based buffer overflow (CVE-ID: CVE-2026-73020)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when the service is accessed locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
614) Heap-based buffer overflow (CVE-ID: CVE-2026-73021)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain SYSTEM privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when operating locally. A local user can exploit the buffer overflow to gain SYSTEM privileges.
615) Use-after-free (CVE-ID: CVE-2026-73022)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Modern Device Management (MDM) when exploiting a race condition locally. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
616) Heap-based buffer overflow (CVE-ID: CVE-2026-73023)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Imaging Component when processing a specially crafted file. A remote attacker can cause a user to open a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file.
617) Heap-based buffer overflow (CVE-ID: CVE-2026-73024)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Services for NFS ONCRPC XDR Driver when processing locally supplied input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
618) Weak Authentication (CVE-ID: CVE-2026-73025)
CWE-ID: CWE-1390 - Weak Authentication
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access mapped storage without CHAP authentication.
The vulnerability exists due to weak authentication in Windows iSCSI when processing specially crafted authentication data sent to an affected iSCSI Target Server. A remote attacker can send specially crafted authentication data to access mapped storage without CHAP authentication.
User interaction is not required.
619) Heap-based buffer overflow (CVE-ID: CVE-2026-73026)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when accessed locally. A local user can exploit the vulnerability to escalate privileges.
620) NULL pointer dereference (CVE-ID: CVE-2026-77489)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to null pointer dereference in Windows Biometric Service when invoked locally. A local user can trigger the null pointer dereference to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
621) Out-of-bounds read (CVE-ID: CVE-2026-77491)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Windows GDI when processing local operations requiring user interaction. A remote attacker can trigger the out-of-bounds read to disclose information.
Successful exploitation could expose small portions of heap memory.
622) Out-of-bounds read (CVE-ID: CVE-2026-77492)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Storage Port Driver when accessing the driver. A local user can access the Storage Port Driver to disclose sensitive information.
The disclosure may expose kernel memory contents to a user-mode process.
623) Double free (CVE-ID: CVE-2026-77493)
CWE-ID: CWE-415 - Double Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a double free in the Microsoft Graphics Component when processing a malicious RTF file. A remote attacker can craft a malicious RTF file to execute arbitrary code.
624) Type Confusion (CVE-ID: CVE-2026-77494)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to type confusion in Windows DHCP Server when handling network requests. A remote attacker can send network requests to cause a denial of service.
625) Heap-based buffer overflow (CVE-ID: CVE-2026-77495)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Imaging Component when processing a specially crafted file. A remote attacker can provide a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file.
626) Out-of-bounds read (CVE-ID: CVE-2026-77498)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when handling network requests. A remote attacker can send a specially crafted network request to cause a denial of service.
627) Type Confusion (CVE-ID: CVE-2026-77499)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to type confusion in Windows DHCP Server when handling network requests. A remote attacker can send specially crafted network requests to cause a denial of service.
628) Release of invalid pointer or reference (CVE-ID: CVE-2026-77500)
CWE-ID: CWE-763 - Release of invalid pointer or reference
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to release of invalid pointer or reference in Windows Device Association Service when handling local interactions. A local user can exploit the service to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
629) Out-of-bounds read (CVE-ID: CVE-2026-77501)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when handling network requests. A remote attacker can send a crafted network request to cause a denial of service.
630) Out-of-bounds read (CVE-ID: CVE-2026-77502)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when handling network requests. A remote attacker can send a network request to cause a denial of service.
631) Out-of-bounds read (CVE-ID: CVE-2026-77503)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows NTFS when handling NTFS operations locally. A remote attacker can exploit the out-of-bounds read locally to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
632) Double free (CVE-ID: CVE-2026-77504)
CWE-ID: CWE-415 - Double Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a double free in Microsoft Office Word when processing a specially crafted file. A remote attacker can send a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file.
633) Use-after-free (CVE-ID: CVE-2026-77505)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DNS Server record-handling logic when processing DNS queries. A remote attacker can send DNS queries and win a timing-dependent race condition to execute arbitrary code.
Only Windows DNS Server instances configured with a server-level DNS plug-in are vulnerable.
634) Out-of-bounds read (CVE-ID: CVE-2026-77886)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when processing network requests. A remote attacker can send a network request that triggers the out-of-bounds read to cause a denial of service.
635) Out-of-bounds read (CVE-ID: CVE-2026-77887)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to execute arbitrary code.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when processing input locally. A local privileged user can trigger the out-of-bounds read to execute arbitrary code.
Successful exploitation depends on a combination of factors that may include the environment, system configuration, and additional security measures.
636) Type Confusion (CVE-ID: CVE-2026-77888)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to type confusion in Windows DHCP Server when handling network requests. A remote attacker can send a crafted network request to cause a denial of service.
637) Type Confusion (CVE-ID: CVE-2026-77889)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to access of resource using incompatible type (\'type confusion\') in Windows DHCP Server when handling network requests. A remote attacker can send a specially crafted network request to cause a denial of service.
638) Type Confusion (CVE-ID: CVE-2026-77890)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to access of a resource using an incompatible type in Windows DHCP Server when handling network requests. A remote attacker can send a specially crafted network request to cause a denial of service.
639) Out-of-bounds read (CVE-ID: CVE-2026-77891)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to execute code.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when exploited locally. A local privileged user can exploit the vulnerability to execute code.
Successful exploitation requires a deep understanding of the system and depends on environmental and system-configuration factors.
640) Protection mechanism failure (CVE-ID: CVE-2026-77892)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to elevate privileges.
The vulnerability exists due to a protection mechanism failure in Windows Boot Manager when subjected to a physical attack. An attacker with physical access can perform a physical attack to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
641) Out-of-bounds read (CVE-ID: CVE-2026-77893)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when handling network traffic. A remote attacker can send network traffic to cause a denial of service.
642) Race condition (CVE-ID: CVE-2026-77894)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a race condition in Windows Installer when concurrently executing using a shared resource. A local user can win a race condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
643) Out-of-bounds read (CVE-ID: CVE-2026-77895)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows DHCP Server when processing network traffic. A remote attacker can send network traffic that triggers the flaw to cause a denial of service.
644) Integer overflow (CVE-ID: CVE-2026-77896)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow or wraparound in Remote Desktop Client when interacting with the client over a network. A remote attacker can trigger the integer overflow or wraparound to cause a denial of service.
User interaction is required.
645) Use-after-free (CVE-ID: CVE-2026-77899)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Security Center when exploiting a race condition. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
646) Heap-based buffer overflow (CVE-ID: CVE-2026-77904)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Volume Manager Extension Driver when handling input locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
647) Use-after-free (CVE-ID: CVE-2026-77905)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Management Instrumentation when Windows Management Instrumentation is used. A local user can win a race condition to escalate privileges.
Successful exploitation could result in SYSTEM privileges.
648) Untrusted Pointer Dereference (CVE-ID: CVE-2026-78444)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to untrusted pointer dereference in Windows Failover Cluster when handling a specially crafted network packet. A remote attacker can send a specially crafted packet to an affected service to execute arbitrary code.
Successful exploitation requires winning a race condition.
649) Use-after-free (CVE-ID: CVE-2026-78445)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Windows Services for NFS ONCRPC XDR Driver when processing a specially crafted call to a Network File System service. A remote attacker can make a specially crafted call to a Network File System service to execute arbitrary code.
650) Use-after-free (CVE-ID: CVE-2026-78446)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in Windows Distributed File System (DFS) when handling network requests. A remote user can send a specially crafted network request to cause a denial of service.
651) Heap-based buffer overflow (CVE-ID: CVE-2026-78447)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
652) Heap-based buffer overflow (CVE-ID: CVE-2026-78448)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing data locally. A local user can trigger the overflow to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
653) Use-after-free (CVE-ID: CVE-2026-78449)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Reliable Multicast Transport Driver (RMCAST) when processing a specially crafted network packet. A remote attacker can send a specially crafted packet to an affected service to execute arbitrary code.
Successful exploitation requires a deep understanding of the system and depends on environmental, configuration, and security-measure factors.
654) Use-after-free (CVE-ID: CVE-2026-78450)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Reliable Multicast Transport Driver (RMCAST) when processing a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
Successful exploitation requires winning a race condition. No user interaction is required.
655) Untrusted Pointer Dereference (CVE-ID: CVE-2026-78451)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to elevate privileges.
The vulnerability exists due to untrusted pointer dereference in Microsoft Windows SCSI Class System File when performing a physical attack. An attacker with physical access can exploit the vulnerability to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
656) Out-of-bounds read (CVE-ID: CVE-2026-78452)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Windows SCSI Class System File when processing a physical attack. An attacker with physical access can exploit the out-of-bounds read to disclose sensitive information.
The disclosed information may include certain kernel memory content.
657) Integer underflow (CVE-ID: CVE-2026-78453)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to integer underflow in Microsoft Windows SCSI Class System File when handling network input. A remote attacker can trigger the vulnerability over a network to disclose information.
User interaction is required.
658) Out-of-bounds read (CVE-ID: CVE-2026-78454)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the Windows CD-ROM Driver when exploiting the driver locally. A local user can exploit the out-of-bounds read to disclose sensitive information.
Disclosed information may include certain kernel memory content.
659) Out-of-bounds read (CVE-ID: CVE-2026-78455)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to disclose information.
The vulnerability exists due to out-of-bounds read in Xbox when performing a physical attack. An attacker with physical access can perform a physical attack to disclose information.
User interaction is required.
660) Use-after-free (CVE-ID: CVE-2026-78457)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Security Health Service when winning a race condition. A local user can win a race condition to elevate privileges.
Successful exploitation may grant SYSTEM privileges.
661) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-78464)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a time-of-check time-of-use race condition in Windows MIDI Service Module when winning a race condition locally. A local user can exploit the race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
662) Out-of-bounds read (CVE-ID: CVE-2026-78508)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the Windows CD-ROM Driver when subjected to a physical attack. An attacker with physical access can perform a physical attack to disclose sensitive information.
The disclosed information may include kernel-space memory contents accessible from a user-mode process.
663) Buffer over-read (CVE-ID: CVE-2026-78516)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to buffer over-read in Windows Storage when processing physical attack input. An attacker with physical access can trigger the buffer over-read to disclose sensitive information.
User interaction is required.
664) Use-after-free (CVE-ID: CVE-2026-78523)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in Windows DNS when processing network requests. A remote attacker can send network requests to the DNS server to cause a denial of service.
665) Heap-based buffer overflow (CVE-ID: CVE-2026-80075)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Work Folders when using Windows Work Folders. A local user can exploit the heap-based buffer overflow to elevate privileges.
666) Untrusted Pointer Dereference (CVE-ID: CVE-2026-80083)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to untrusted pointer dereference in Windows Hyper-V when processing a specially crafted application on a Hyper-V guest. A local user can run a specially crafted application on a Hyper-V guest to execute arbitrary code.
The code executes on the Hyper-V host operating system.
667) Use-after-free (CVE-ID: CVE-2026-80093)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Cloud Files Mini Filter Driver when winning a race condition. A local user can win a race condition to escalate privileges.
668) Out-of-bounds read (CVE-ID: CVE-2026-80096)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to an out-of-bounds read in Windows Remote Desktop Services when processing specially crafted data sent through Remote Desktop Protocol with USB redirection enabled. A remote user can send specially crafted data to elevate privileges.
USB redirection must be enabled.
669) Heap-based buffer overflow (CVE-ID: CVE-2026-81354)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Hello Face secure sensor adapter when processing malformed face data. A local privileged user can submit malformed face data to the Windows Hello Face secure sensor adapter to elevate privileges.
User interaction is not required.
670) Heap-based buffer overflow (CVE-ID: CVE-2026-81355)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to execute code locally.
The vulnerability exists due to heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver when processing data. A local privileged user can trigger the heap-based buffer overflow to execute code locally.
Successful exploitation requires a deep understanding of the system and depends on environmental and system-configuration factors, as well as the presence of additional security measures.
671) Untrusted Pointer Dereference (CVE-ID: CVE-2026-83498)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave when dereferencing an untrusted pointer. A local user can exploit the untrusted pointer dereference to elevate privileges.
Successful exploitation could leak data from the target enclave or execute code in the context of the target enclave.
672) Out-of-bounds read (CVE-ID: CVE-2026-83501)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose information.
The vulnerability exists due to an out-of-bounds read in the Windows Virtualization-Based Security (VBS) Enclave when processing local input. A local user can trigger the out-of-bounds read to disclose information.
Successful exploitation could allow VTL0 to view Virtual Trust Level 1 (VTL1) data.
673) Untrusted Pointer Dereference (CVE-ID: CVE-2026-83939)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to execute code in Virtual Trust Level 1 (VTL1).
The vulnerability exists due to untrusted pointer dereference in Windows Secure Kernel Mode when submitting a specially crafted Code Integrity policy to an affected system. A local privileged user can submit a specially crafted Code Integrity policy to execute code in Virtual Trust Level 1 (VTL1).
674) Use-after-free (CVE-ID: CVE-2026-83940)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Device Association Service when handling local operations. A local user can win a race condition to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
675) Missing Authorization (CVE-ID: CVE-2026-83942)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges to SYSTEM.
The vulnerability exists due to missing authorization in the Windows Kernel when accessing the kernel locally. A local user can exploit the missing authorization to elevate privileges to SYSTEM.
676) Heap-based buffer overflow (CVE-ID: CVE-2026-83952)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Resilient File System (ReFS) when handling local operations. A local user can exploit the overflow to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
677) Heap-based buffer overflow (CVE-ID: CVE-2026-83954)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
678) Heap-based buffer overflow (CVE-ID: CVE-2026-83955)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when handling local input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
679) Heap-based buffer overflow (CVE-ID: CVE-2026-83967)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to heap-based buffer overflow in Windows Biometric Service when exploited locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
680) Use-after-free (CVE-ID: CVE-2026-83968)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Biometric Service when processing local requests. A local user can trigger the use-after-free to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
681) Heap-based buffer overflow (CVE-ID: CVE-2026-83969)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when exploiting the service locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
682) Heap-based buffer overflow (CVE-ID: CVE-2026-83970)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when the service is accessed locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
683) Heap-based buffer overflow (CVE-ID: CVE-2026-83971)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
684) Heap-based buffer overflow (CVE-ID: CVE-2026-83972)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Biometric Service when processing input locally. A local user can exploit the vulnerability to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
685) Heap-based buffer overflow (CVE-ID: CVE-2026-83973)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing locally supplied input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
686) Heap-based buffer overflow (CVE-ID: CVE-2026-83974)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
687) Heap-based buffer overflow (CVE-ID: CVE-2026-83975)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when the service is accessed locally. A local user can exploit the vulnerability to elevate privileges.
688) Heap-based buffer overflow (CVE-ID: CVE-2026-83976)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when accessed locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation can grant SYSTEM privileges.
689) Heap-based buffer overflow (CVE-ID: CVE-2026-83977)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in the Windows Biometric Service when exploited locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
690) Heap-based buffer overflow (CVE-ID: CVE-2026-83978)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input locally. A local user can trigger the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
691) Use-after-free (CVE-ID: CVE-2026-83979)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to use-after-free in Windows Biometric Service when exploiting the service locally. A local user can trigger the use-after-free condition to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
692) Heap-based buffer overflow (CVE-ID: CVE-2026-83980)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when handling input locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
693) Heap-based buffer overflow (CVE-ID: CVE-2026-83981)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing locally initiated operations. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
694) Heap-based buffer overflow (CVE-ID: CVE-2026-83982)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input. A local user can exploit the heap-based buffer overflow to elevate privileges.
695) Heap-based buffer overflow (CVE-ID: CVE-2026-83983)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input. A local user can exploit the vulnerability to elevate privileges.
696) Heap-based buffer overflow (CVE-ID: CVE-2026-83985)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing local input. A local user can exploit the overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
697) Heap-based buffer overflow (CVE-ID: CVE-2026-83986)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when processing input. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
698) Heap-based buffer overflow (CVE-ID: CVE-2026-83987)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when handling locally supplied input. A local user can trigger the overflow to elevate privileges.
Successful exploitation can result in SYSTEM privileges.
699) Heap-based buffer overflow (CVE-ID: CVE-2026-83988)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Biometric Service when exploiting the vulnerability locally. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could result in SYSTEM privileges.
700) Out-of-bounds read (CVE-ID: CVE-2026-83989)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the Windows Services for NFS ONCRPC XDR Driver when processing network requests. A remote attacker can send a specially crafted network request to cause a denial of service.
701) Stack-based buffer overflow (CVE-ID: CVE-2026-83990)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Graphics Component when processing unspecified local input. A local user can exploit the overflow to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
702) Missing Authentication for Critical Function (CVE-ID: CVE-2026-83991)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make unauthorized modifications to protected system data.
The vulnerability exists due to missing authentication for critical function in Windows Cloud Files Mini Filter Driver when invoking critical functions. A local user can invoke critical functions without authentication to make unauthorized modifications to protected system data.
703) Heap-based buffer overflow (CVE-ID: CVE-2026-83992)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Imaging Component when processing a specially crafted file. A remote attacker can persuade a user to open a specially crafted file to execute arbitrary code.
User interaction is required.
704) Heap-based buffer overflow (CVE-ID: CVE-2026-83995)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows NTFS when processing NTFS operations. A local user can trigger the heap-based buffer overflow to escalate privileges.
705) Heap-based buffer overflow (CVE-ID: CVE-2026-83996)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Error Reporting when handling error reports. A local user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation can elevate integrity from Low Integrity Level in a contained sandboxed environment to Medium Integrity Level.
706) Use-after-free (CVE-ID: CVE-2026-83997)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Windows Message Queuing when processing a specially crafted packet sent to an affected service over the network. A remote attacker can send a specially crafted packet to execute arbitrary code.
Successful exploitation requires winning a race condition.
707) Heap-based buffer overflow (CVE-ID: CVE-2026-83998)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Remote Desktop Client when processing a malicious server response. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
708) Link following (CVE-ID: CVE-2026-83999)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper link resolution before file access (\'link following\') in the Windows Resilient File System (ReFS) Deduplication Service when accessing files. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
709) Heap-based buffer overflow (CVE-ID: CVE-2026-84000)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the Microsoft Graphics Component when processing input. A local user can trigger the overflow to execute arbitrary code.
710) Out-of-bounds read (CVE-ID: CVE-2026-84001)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Windows Key Distribution Center when handling network requests. A remote attacker can send a network request to cause a denial of service.
711) Use-after-free (CVE-ID: CVE-2026-85360)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to obtain SYSTEM privileges.
The vulnerability exists due to use-after-free in the Windows Kernel when exploiting the kernel locally. A local user can exploit the use-after-free flaw to obtain SYSTEM privileges.
Successful exploitation requires significant effort and precise conditions.
712) Heap-based buffer overflow (CVE-ID: CVE-2026-85877)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Windows Print Spooler Components when a user connects a Windows client to a malicious server. A remote attacker can cause the client to connect to a malicious server to execute arbitrary code.
User interaction is required.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-50349
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-56172
- https://support.microsoft.com/help/5122876
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-56177
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-56198
- https://support.microsoft.com/help/5122871
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62694
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62697
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62706
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62744
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62759
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62762
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62801
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62810
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62813
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68824
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68825
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68827
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68828
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68830
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68831
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68832
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68833
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68834
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68835
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68837
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68838
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68839
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68840
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68841
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68842
- https://support.microsoft.com/help/5124008
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68843
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68844
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68845
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68846
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68847
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68848
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68849
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68850
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68851
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68852
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68873
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68874
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68875
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68876
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68877
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68878
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68880
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68881
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68884
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68885
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68886
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68887
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68888
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68889
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68890
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68891
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68892
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68893
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68894
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68895
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68896
- https://support.microsoft.com/help/5122882
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68897
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68898
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69265
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69266
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69267
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69269
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69270
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69271
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69272
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69274
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69275
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69276
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69277
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69279
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69280
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69281
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69283
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69284
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69286
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69287
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69288
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69289
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69290
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69291
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69292
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69293
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69294
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69295
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69296
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69297
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69298
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69298
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69299
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69300
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69301
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69303
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69305
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69307
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69308
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69309
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69310
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69311
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69312
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69313
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69314
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69315
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69316
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69317
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69318
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69319
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69321
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69322
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69323
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69324
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69325
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69328
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69329
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69331
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69332
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69333
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69334
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69335
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69336
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69337
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69338
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69339
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69340
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69341
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69342
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69343
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69343
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69344
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69345
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69346
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69347
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69348
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69349
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69350
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69351
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69352
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69353
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69357
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69358
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69359
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69360
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69362
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69364
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69365
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69366
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69366
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69367
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69368
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69369
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69371
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69372
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69373
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69374
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69376
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69377
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69377
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69379
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69381
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69383
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69384
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69385
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69386
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69388
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69389
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69390
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69391
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69392
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69393
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69394
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69395
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69396
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69397
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69398
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69401
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69403
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69404
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69405
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69406
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69407
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69408
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69410
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69412
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69413
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69415
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69416
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69418
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69420
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69421
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69422
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69423
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69424
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69425
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69426
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69427
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69428
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69429
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69430
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69431
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69432
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69433
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69434
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69436
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69438
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69440
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69441
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69443
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69444
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69445
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69447
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69448
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69449
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69450
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69451
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69453
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69455
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69456
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69457
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69458
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69459
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69460
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69461
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69462
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69463
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69466
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69467
- https://support.microsoft.com/help/5122878
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69468
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69469
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69470
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69472
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69473
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69474
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69475
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69476
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69478
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69479
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69480
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69481
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69482
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69483
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69485
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69488
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69489
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69490
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69491
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69492
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69493
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69494
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69495
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69496
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69497
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69498
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69499
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69500
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69501
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69503
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69504
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69505
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69507
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69508
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69509
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69510
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69511
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69512
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69512
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69513
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69514
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69516
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69517
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69518
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69524
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69525
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69527
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69528
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69530
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69531
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69532
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69534
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69535
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69536
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69538
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69539
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69540
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69541
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69542
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69544
- https://support.microsoft.com/help/5124012
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69546
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69547
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69548
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69549
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69551
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69552
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69553
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69554
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69560
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69561
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69563
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69564
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69566
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69567
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69568
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69569
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69571
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69572
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69573
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69574
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69575
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69576
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69576
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69578
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69579
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69580
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69581
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69582
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69583
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69584
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69585
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69586
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69587
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69588
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69589
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69590
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69591
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69592
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69593
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69594
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69595
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69597
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69598
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69599
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69600
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69601
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69602
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69603
- https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5122876
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69604
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69605
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69606
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69607
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69608
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69609
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69610
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69611
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69612
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69613
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69616
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69617
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69618
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69619
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69620
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69621
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69623
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69624
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69625
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69627
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69628
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69630
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69631
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69637
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69638
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69643
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69645
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69648
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69652
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69654
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69669
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69672
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69674
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69676
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69679
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69680
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69681
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69682
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69684
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69685
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69687
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69688
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69689
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69691
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69692
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69693
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69694
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69706
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69707
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69708
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69709
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69710
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69711
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69712
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69713
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69714
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69715
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69717
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69720
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69723
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69725
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69727
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69729
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69730
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69731
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69732
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69735
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69738
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69740
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69741
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69744
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69757
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69758
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69760
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69761
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69762
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69768
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69769
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69770
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69771
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69772
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69773
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69775
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69775
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69777
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69779
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69781
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69782
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69784
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69785
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69786
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69787
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69790
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69791
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69792
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69792
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69793
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69794
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69799
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69801
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69803
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69807
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69808
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69809
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69813
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69814
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69816
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69817
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69818
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69819
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69820
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69821
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69822
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69824
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69826
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69827
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69829
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69832
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69834
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69838
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69839
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69841
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69844
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69845
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69846
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69847
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69852
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69853
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69858
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69859
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69860
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69862
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69864
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69866
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69874
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69875
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69876
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69878
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69881
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69889
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69890
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69891
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69895
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69896
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69900
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69906
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69907
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69910
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69911
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69921
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69929
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69930
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69989
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70019
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70065
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70091
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70124
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70145
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70203
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70283
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70289
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70290
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70296
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70342
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70562
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70563
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70564
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70565
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70567
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70568
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70569
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70570
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70572
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70573
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70574
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70575
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70577
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70578
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70579
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70581
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70582
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70583
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70584
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70585
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70586
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-70587
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71329
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71330
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71332
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71333
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71334
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71336
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71337
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71338
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71339
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71340
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71341
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71342
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71343
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71345
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71348
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71349
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71350
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71351
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71352
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71353
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72926
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72927
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72928
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72929
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72930
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72931
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72932
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72932
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72933
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72935
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72936
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72937
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72939
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72940
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72941
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72942
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72943
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72944
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72945
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72946
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72947
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72948
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72949
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72950
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72952
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72953
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72954
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72957
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72958
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72959
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72960
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72961
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72962
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72962
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72963
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72964
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72965
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72966
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72967
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72978
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72979
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72980
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72981
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72982
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72983
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72985
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72986
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72987
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72988
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72989
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72990
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72991
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72992
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72993
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72994
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72995
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72996
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72997
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72999
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73000
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73001
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73002
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73003
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73004
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73005
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73006
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73007
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73008
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73008
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73009
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73010
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73011
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73012
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73013
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73014
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73015
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73016
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73017
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73018
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73019
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73020
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73021
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73022
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73023
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73024
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73025
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-73026
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73026
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77489
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77491
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77492
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77493
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77494
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77495
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77498
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77499
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77500
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77501
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77502
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77503
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77504
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77505
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77886
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77887
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77888
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77889
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77890
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77891
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77892
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77893
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77894
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77895
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77896
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77899
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77904
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77905
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78444
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78445
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78446
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78447
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78448
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78449
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78450
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78451
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78452
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78453
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78454
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78455
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78457
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78464
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78508
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78516
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78523
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80075
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80083
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80093
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80096
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81354
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81355
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83498
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83501
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83939
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83940
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83942
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83952
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83954
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83955
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83967
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83968
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83969
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83970
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83971
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83972
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83973
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83974
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83975
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83976
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83977
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83978
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83979
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83980
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83981
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83982
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83983
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83985
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83986
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83987
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83988
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83989
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83990
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83991
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83992
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83992
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83995
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83996
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83997
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83998
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83999
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-84000
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-84001
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-85360
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-85877