Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-50440

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 25H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
2

CVE-2026-5044

A security vulnerability has been detected in Belkin F9K1122 1.00.33. This affects the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler. Such manipulation of the argument webpage leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Belkin
Product
F9K1122
Provider severity
HIGH
Conflicts
2

CVE-2026-50439

Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 10 Version 1809, Windows 11 version 26H1, Windows 11 Version 24H2, Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-50438

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft PC Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-50437

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows 10 Version 1607, Windows Server 2016, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2022, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50436

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50435

Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 1607, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 1809, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-50434

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2022, Windows 11 version 26H1, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50433

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 25H2, Windows Server 2012, Windows 10 Version 1809, Windows Server 2025, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2012 R2, Windows 10 Version 22H2, Windows Server 2012 (Server Core installation), Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-50432

Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2025, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2016 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50431

Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows Server 2012, Windows 11 version 26H1, Windows Server 2012 R2, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2022, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50430

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5043

A weakness has been identified in Belkin F9K1122 1.00.33. The impacted element is the function formSetPassword of the file /goform/formSetPassword of the component Parameter Handler. This manipulation of the argument webpage causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Belkin
Product
F9K1122
Provider severity
HIGH
Conflicts
2

CVE-2026-50429

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 25H2, Windows 10 Version 1607, Windows 11 version 26H1, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
2

CVE-2026-50428

Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
HIGH
Conflicts
0

CVE-2026-50427

Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
2

CVE-2026-50426

Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2019, Windows Server 2012
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50425

Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50424

Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-50423

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-50422

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows Server 2016, Windows Server 2012 R2, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2025, Windows 10 Version 22H2, Windows 10 Version 1809, Windows 10 Version 1607, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50421

Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 10 Version 1607, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50420

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5042

A security flaw has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formCrossBandSwitch of the file /goform/formCrossBandSwitch of the component Parameter Handler. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Belkin
Product
F9K1122
Provider severity
HIGH
Conflicts
2

CVE-2026-50419

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows Server 2012 R2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows Server 2012, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation)
Provider severity
LOW
Conflicts
1

CVE-2026-50418

Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2025, Windows 11 version 26H1, Windows Server 2022, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50417

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows Server 2022, Windows Server 2016, Windows Server 2025, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2012, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2019
Provider severity
HIGH
Conflicts
2

CVE-2026-50416

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation)
Provider severity
LOW
Conflicts
1

CVE-2026-50415

Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2019, Windows Server 2022, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2025, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50414

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-50413

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2025, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-50412

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2016, Windows Server 2025, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-50411

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft .NET Framework 3.5 AND 4.8, Windows Server 2025, Windows Server 2012, Windows Server 2022, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 4.8.1, Windows 11 Version 25H2, Windows Server 2019, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Microsoft .NET Framework 4.8, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50410

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 1809, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2022, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-5041

A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the function fwrite of the file admin/pageMail.php. The manipulation of the argument mailSubject/mailMessage leads to command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
code-projects
Product
Chamber of Commerce Membership Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-50409

Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2016, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 11 version 26H1
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50408

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Excel 2016, Office Online Server, Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50407

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50406

Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50405

Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2025, Windows Server 2012 R2, Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50404

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
2

CVE-2026-50403

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-50402

Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2016, Windows Server 2025, Windows Server 2012
Provider severity
HIGH
Conflicts
2

CVE-2026-50401

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2022, Windows Server 2025, Windows 10 Version 22H2, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50400

Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2022, Windows Server 2012, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2012 R2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-5040

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Deco M5 Deco M5 V1
Provider severity
HIGH
Conflicts
0

CVE-2026-50399

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50398

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-50397

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2022, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2025, Windows Server 2019, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012, Windows Server 2016 (Server Core installation), Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-50396

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1