cve
Vulnerability watch Full archive
idvulnerabilityseveritypublished
CVE-2026-50421Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50422Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50423Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 CVE-2026-50424Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.Microsoft Windows 11 24h2 High CVSS 7.5 CVE-2026-50425Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 CVE-2026-50427Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50429Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 8.2 CVE-2026-50433Use after free in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50435Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50436Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50438Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.Microsoft Pc Manager High CVSS 8.8 CVE-2026-50439Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-50440Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50441Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50444Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50445Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50447Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-50448Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50449Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-50450Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-50451Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50452Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1809 High CVSS 8.1 CVE-2026-50454Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50457Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50458Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50459Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 CVE-2026-50460Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1809 High CVSS 8.1 CVE-2026-50461Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50462External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50463Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1809 High CVSS 7.5 CVE-2026-50465Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.Microsoft Windows 11 24h2 High CVSS 7.1 CVE-2026-50466Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50467Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-50469Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50470Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50471Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50474Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50476Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50477Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50478Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50479Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50480Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50482Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50484Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50486Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 CVE-2026-50487Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 Critical CVSS 9.8 CVE-2026-50488Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50489Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50490Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50491Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50493Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50494Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50496Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50497Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50498Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityMicrosoft Windows 10 1607 High CVSS 7.8 CVE-2026-50499Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50500Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50501Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50502Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50503Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50504Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50505Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50506Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.Microsoft Asp.net Core Odata High CVSS 7.5 CVE-2026-50509Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50510Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.Microsoft Github Copilot High CVSS 7.8 CVE-2026-50518Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-50520Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.Microsoft Visual Studio Code High CVSS 8.4 CVE-2026-50524Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.Microsoft .net High CVSS 7.5 CVE-2026-50525Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50527Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50528Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.Microsoft .net High CVSS 8.2 CVE-2026-50646Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Microsoft .net Framework High CVSS 7.8 CVE-2026-50647Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50648Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50649Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Microsoft .net Framework High CVSS 7.8 CVE-2026-50650Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.Microsoft .net Framework High CVSS 7.8 CVE-2026-50651Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.Microsoft .net High CVSS 7.5 CVE-2026-50652Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50653Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50655Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50658Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.Microsoft Defender For Endpoint High CVSS 7 CVE-2026-50663Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.Microsoft Age Of Empires Ii High CVSS 8.8 CVE-2026-50666Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50667Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50669Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50670Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50672Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-50673Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50674Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50675Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-50676Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50677Use after free in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50679Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50680Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50682Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.Microsoft Windows 10 21h2 High CVSS 7.1 CVE-2026-50683Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.Microsoft Windows 10 1607 High CVSS 8 CVE-2026-50685Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50686Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 CVE-2026-50687Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50688Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 9001–9100 / 11286 CVE