Microsoft
- 478
- vulnérabilités suivies
- 5
- en exploitation active
- 32
- critiques
- 22 juillet 2026
- dernière publication
cve
Veille des vulnérabilités
identifiantvulnérabilitésévéritépublié
CVE-2026-50522Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.Microsoft SharePoint Critique CVSS 9.8 CVE-2026-56171Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Remote Desktop Web Client Élevée CVSS 7.5 CVE-2026-58598Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7 CVE-2026-58644Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.Microsoft SharePoint Critique CVSS 9.8 CVE-2026-59117Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.Microsoft Terminal Élevée CVSS 7.5 CVE-2026-40378Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-40400Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8 CVE-2026-42900Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 CVE-2026-42975Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.Microsoft Windows 10 1607 Élevée CVSS 8.8 CVE-2026-42982Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-42990Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-44800Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 Élevée CVSS 7.8 CVE-2026-44806Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-45646Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.Microsoft Asp.net Core Odata Élevée CVSS 7.5 CVE-2026-47290Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-47295Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.Microsoft Sql Server 2016 Élevée CVSS 8.8 CVE-2026-47296Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.Microsoft Sql Server 2016 Élevée CVSS 7.8 CVE-2026-47300Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.Microsoft .net Élevée CVSS 8.8 CVE-2026-47301Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.Microsoft Configuration Manager 2503 Élevée CVSS 8.8 CVE-2026-47302Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.Microsoft .net Framework Élevée CVSS 7.5 CVE-2026-47303Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.Microsoft .net Élevée CVSS 8.8 CVE-2026-47304Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.Microsoft .net Framework Critique CVSS 9.8 CVE-2026-47305Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.Microsoft Visual Studio 2022 Élevée CVSS 7.8 CVE-2026-47632Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.Microsoft Azure Connected Machine Agent Élevée CVSS 8.8 CVE-2026-47642Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-48561Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.Microsoft 365 Copilot Critique CVSS 9.6 CVE-2026-48564Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.8 CVE-2026-48571Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 Élevée CVSS 7 CVE-2026-48572Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 Élevée CVSS 7 CVE-2026-48581Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.Microsoft Surface Go 2 1901 Firmware Élevée CVSS 7.8 CVE-2026-49162Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-49164Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-49165Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.Microsoft Windows 10 1607 Élevée CVSS 7.1 CVE-2026-49166Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-49167Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-49169Use after free in DNS Server allows an authorized attacker to execute code over a network.Microsoft Windows Server 2025 Élevée CVSS 8.8 CVE-2026-49170Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-49171Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49172Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-49173Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 26h1 Élevée CVSS 7.8 CVE-2026-49175Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.8 CVE-2026-49176Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49178Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.8 CVE-2026-49181Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-49183Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7 CVE-2026-49184Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49783Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49784Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-49787Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-49788Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-49789Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49790Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityMicrosoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49791Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49792Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49793Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49795Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 8.8 CVE-2026-49796Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49797Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-49798Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Critique CVSS 9.3 CVE-2026-49800Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-49802Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-49803Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-49805Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-49806Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-49808Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-50293Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.8 CVE-2026-50296Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-50297Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-50301Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-50304Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-50305Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-50306Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50307Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-50308Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50309Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50311Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50312Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50313Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50314Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-50315Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-50317Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-50318Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50321Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-50322Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-50323Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-50325Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-50326Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.8 CVE-2026-50327Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-50328Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-50329Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-50330Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-50331Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50332Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50333Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50335Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-50336Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-50337Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-50338Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.Microsoft Azure Spring Cloud Élevée CVSS 8.2 CVE-2026-50340Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 Élevée CVSS 8.8 CVE-2026-50342Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 8.8 Les 100 plus récentes.