Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-50348

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2025, Windows 11 version 26H1, Windows Server 2022
Provider severity
HIGH
Conflicts
2

CVE-2026-50347

Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2012, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
2

CVE-2026-50346

Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2016, Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2012, Windows Server 2022, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows Server 2019, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-50345

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
2

CVE-2026-50344

Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows Server 2019, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2012, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-50343

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2025, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50342

Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50341

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2012, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2022, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows 10 Version 1607
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50340

Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-5034

A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation of the argument cos_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
code-projects
Product
Accounting System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-50339

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2025, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50338

Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Spring Apps
Provider severity
HIGH
Conflicts
0

CVE-2026-50337

Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2016, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2022, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-50336

Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50335

Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-50334

Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2012, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows Server 2012 R2, Windows Server 2016, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50333

Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50332

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 Version 24H2, Windows Server 2019, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows 10 Version 1809, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-50331

Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2019, Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2025, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50330

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2012, Windows Server 2019, Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-5033

A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The manipulation of the argument cos_id results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

PUBLISHED
Vendor
code-projects
Product
Accounting System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-50329

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2025, Windows Server 2019, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50328

Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2022, Windows Server 2016, Windows Server 2025, Windows Server 2012, Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-50327

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 24H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50326

Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 10 Version 21H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-50325

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2019, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows Server 2012, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1607, Windows 11 version 26H1, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-50324

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 10 Version 1809, Windows Server 2012 R2, Windows 10 Version 1607, Windows Server 2016, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Windows Server 2025, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 3.5 AND 4.8, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 4.8, Windows Server 2019 (Server Core installation), Microsoft .NET Framework 4.8.1, Microsoft .NET Framework 3.5 AND 4.8.1, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50323

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-50322

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-50321

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2016, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2012, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
2

CVE-2026-5032

The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which causes raw mfunc/mclude dynamic fragment HTML comments — including the W3TC_DYNAMIC_SECURITY security token — to be rendered in the page source. This makes it possible for unauthenticated attackers to discover the value

PUBLISHED
Vendor
boldgrid
Product
W3 Total Cache
Provider severity
HIGH
Conflicts
0

CVE-2026-50318

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 10 Version 1809, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2025, Windows 10 Version 1607, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50317

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-50316

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2022, Windows 11 version 26H1
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50315

Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50314

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-50313

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2019, Windows Server 2025, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 R2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-50312

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012, Windows Server 2016, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2025, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2022, Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50311

Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows Server 2019, Windows 11 version 26H1, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-50310

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2022, Windows 11 Version 25H2, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5031

A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_route=settings/users-view/ of the component Endpoint. The manipulation of the argument ID results in improper control of resource identifiers. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
BichitroGan
Product
ISP Billing Software
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50309

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows 10 Version 22H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2025, Windows Server 2022, Windows Server 2012
Provider severity
HIGH
Conflicts
1

CVE-2026-50308

Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012, Windows Server 2012 R2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
2

CVE-2026-50307

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2019, Windows 11 Version 25H2, Windows Server 2022, Windows 11 Version 24H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50306

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2025, Windows Server 2012, Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2016, Windows Server 2019, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
2

CVE-2026-50305

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
2

CVE-2026-50304

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Windows Server 2012 R2, Windows Server 2022, Windows 10 Version 1809, Microsoft .NET Framework 4.8.1, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows Server 2012, Microsoft .NET Framework 3.5 AND 4.7.2, Windows 10 Version 1607, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2016, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft .NET Framework 3.5 AND 4.8, Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8
Provider severity
HIGH
Conflicts
1

CVE-2026-50303

Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2022, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50302

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 version 26H1, Windows Server 2025, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50301

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office 2016
Provider severity
HIGH
Conflicts
1