Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-50394

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 10 Version 1607, Windows Server 2012 R2, Windows 10 Version 21H2, Windows Server 2019, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2016, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 1809
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50393

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50392

Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-50391

Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 1607, Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-50390

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2012, Windows 11 Version 25H2, Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-5039

TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if device is left in default configuration. A network-adjacent attacker can exploit this weakness to gain unauthorized access to the protocol, read debug data, modify certain device configuration values, and trigger device reboot, resulting in loss of integrity and a denial-of-service condition.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
TL-WL841N v13
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50389

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows Server 2025, Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2016, Windows 10 Version 1607, Windows 10 Version 22H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50388

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012, Windows Server 2016, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2012 R2, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-50387

Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Microsoft Office for Android, Windows 11 Version 25H2, Windows Server 2012, Microsoft Office LTSC for Mac 2021, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2016, Windows 10 Version 1607, Windows Server 2022, Windows 10 Version 21H2, Microsoft Office 365 for Mac, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Microsoft Office LTSC for Mac 2024, Windows Server 2019, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-50386

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012, Windows 11 version 26H1, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 R2, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-50385

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-50384

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2022, Windows 11 Version 24H2, Windows Server 2019, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 25H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
2

CVE-2026-50383

Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2019, Windows Server 2025, Windows 10 Version 22H2, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50382

Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2019, Windows 10 Version 1809, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-50381

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2022, Windows 11 version 26H1, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50380

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2019, Windows Server 2025, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 11 Version 24H2
Provider severity
CRITICAL
Conflicts
1

CVE-2026-5038

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2

PUBLISHED
Vendor
multer
Product
multer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50379

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
2

CVE-2026-50378

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2019, Windows 11 Version 24H2, Windows Server 2022, Windows 10 Version 21H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-50377

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows Server 2016, Windows 10 Version 1607, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50376

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows Server 2012, Windows Server 2016, Windows 11 version 26H1
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50375

Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows 11 Version 25H2, Windows 10 Version 1809
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50374

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2022, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50373

Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-50372

Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows 10 Version 1607, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
2

CVE-2026-50371

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2012, Windows Server 2016, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows 11 version 26H1, Windows 10 Version 1607, Windows Server 2022
Provider severity
HIGH
Conflicts
2

CVE-2026-50370

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2012 R2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows 10 Version 1809, Windows Server 2012, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-5037

A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c of the component mxmlIndexNew. Executing a manipulation of the argument tempr can lead to stack-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. This patch is called 6e27354466092a1ac65601e01ce6708710bb9fa5. A patch should be applied to remediate this issue.

PUBLISHED
Vendor
n/a
Product
mxml
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-50369

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025, Windows Server 2022, Windows Server 2016, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1607
Provider severity
HIGH
Conflicts
2

CVE-2026-50368

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2022, Windows Server 2025, Microsoft .NET Framework 4.8, Microsoft .NET Framework 3.5 AND 4.8.1, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Microsoft .NET Framework 4.8.1, Microsoft .NET Framework 3.5 AND 4.7.2, Windows Server 2025 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8, Windows Server 2016 (Server Core installation), Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-50367

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2019, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-50366

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2022, Windows 11 version 26H1, Windows Server 2019, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50365

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 11 version 26H1, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2012, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016, Windows 11 Version 25H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-50364

Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50363

Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2019, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 1809, Windows Server 2012 R2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-50362

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2019, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 21H2, Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50361

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
2

CVE-2026-50360

Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2022, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-5036

A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the file /goform/DhcpListClient of the component Endpoint. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
Tenda
Product
4G06
Provider severity
HIGH
Conflicts
2

CVE-2026-50359

Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2025, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-50358

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-50357

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2016, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-50356

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows Server 2022, Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2016, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50355

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft .NET Framework 3.5 AND 4.7.2, Windows Server 2019, Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012 R2, Microsoft .NET Framework 3.5 AND 4.8, Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8.1, Windows Server 2012, Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 4.8
Provider severity
HIGH
Conflicts
1

CVE-2026-50354

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2022, Windows 10 Version 1607, Windows Server 2025, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-50353

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50352

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows 11 Version 24H2, Windows Server 2019, Windows 10 Version 1607, Windows Server 2012 R2, Windows Server 2016, Windows Server 2025, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50351

Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016, Windows 10 Version 22H2, Windows Server 2019, Windows 11 Version 25H2, Windows Server 2012, Windows Server 2022, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-50350

Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 22H2, Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5035

A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation of the argument en_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Accounting System
Provider severity
HIGH, MEDIUM
Conflicts
2