CWE-1220
- 8
- vulnerabilities tracked
- 1
- under active exploitation
- 17 August 2026
- latest publication
cve
Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-40145A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.NVD analysis in progress High CVSS 7.1 CVE-2026-62721Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-48581Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.Microsoft Surface Go 2 1901 Firmware High CVSS 7.8 CVE-2026-49170Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50405Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50502Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-55006Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.Microsoft Exchange Server High CVSS 7.8 CVE-2026-56155Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.Microsoft Active Directory Federation Services Critical CVSS 7.8