Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-45648

Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-45647

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Defender for Endpoint for Mac
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45646

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
AspNetCore.OData, AspNet.OData
Provider severity
HIGH
Conflicts
1

CVE-2026-45645

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office 2016, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-45644

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Live Share Canvas SDK
Provider severity
HIGH
Conflicts
0

CVE-2026-45643

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-45642

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 R2, Windows Server 2025, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2012, Windows Server 2019, Windows 11 version 23H2, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation)
Provider severity
LOW
Conflicts
1

CVE-2026-45641

Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows Server 2022, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-45640

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2022, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows Server 2025, Windows 11 version 23H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-4564

A security vulnerability has been detected in yangzongzhuan RuoYi up to 4.8.2. This issue affects some unknown processing of the file /monitor/job/ of the component Quartz Job Handler. Such manipulation of the argument invokeTarget leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
yangzongzhuan
Product
RuoYi
Provider severity
MEDIUM
Conflicts
2

CVE-2026-45639

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows App Client for Windows Desktop, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows Server 2016, Windows Server 2012, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Remote Desktop client for Windows Desktop
Provider severity
HIGH
Conflicts
1

CVE-2026-45638

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 21H2, Windows Server 2019, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 1607, Windows Server 2016, Windows Server 2012, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-45637

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2022, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 11 version 23H2, Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2019, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-45636

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 24H2, Windows Server 2016, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-45635

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2016, Windows Server 2012, Windows 11 version 23H2, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-45634

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2012 R2, Windows 11 version 23H2, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45633

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges.

PUBLISHED
Vendor
Dokploy
Product
dokploy
Provider severity
CRITICAL
Conflicts
0

CVE-2026-45632

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to other organizations if they know the scheduleId/serverId. Schedule types server and dokploy-server write and execute scripts on the host or remote servers, enabling RCE on the Dokploy host or a target server.

PUBLISHED
Vendor
Dokploy
Product
dokploy
Provider severity
CRITICAL
Conflicts
1

CVE-2026-45631

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign-in as admin, and execute commands on the host via the built-in SSH terminal. This vulnerability is fixed in 0.29.3.

PUBLISHED
Vendor
Dokploy
Product
dokploy
Provider severity
CRITICAL
Conflicts
0

CVE-2026-45630

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote servers via unsanitized echo shell interpolation.

PUBLISHED
Vendor
Dokploy
Product
dokploy
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4563

A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization bypass. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
n/a
Product
MacCMS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-45629

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote servers managed by Dokploy, leading to full server compromise.

PUBLISHED
Vendor
Dokploy
Product
dokploy
Provider severity
CRITICAL
Conflicts
0

CVE-2026-45628

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via child_process.exec() (which runs through /bin/sh -c). User-supplied branch names, repository URLs, and Docker credentials are interpolated directly into these commands without escaping. This requires an authenticated user with application create/edit privileges.

PUBLISHED
Vendor
Dokploy
Product
dokploy
Provider severity
CRITICAL
Conflicts
1

CVE-2026-45627

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via strings.ReplaceAll with no escaping. The substitution lands inside a <style> element of the embedded logo.svg, allowing an attacker to close the style block and inject executable <script> content. Because the response is served as image/svg+xml and Arcane set

PUBLISHED
Vendor
getarcaneapp
Product
arcane
Provider severity
HIGH
Conflicts
0

CVE-2026-45626

Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is passed to a shell command (sh -c "find … | while …") inside an Arcane helper container. The path sanitiser blocks ../ traversal but does not strip Bourne-shell metacharacters such as $() or backticks, and strconv.Quote only escapes Go string metacharacters, not shell substitution sequences. Any authe

PUBLISHED
Vendor
getarcaneapp
Product
arcane
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45625

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps source repositories and their stored credentials. Eight of those endpoints (list, create, get, update, delete, test, listBranches, browseFiles) never call the checkAdmin(ctx) helper that every other admin-managed resource (container registries, environment

PUBLISHED
Vendor
getarcaneapp
Product
arcane
Provider severity
CRITICAL
Conflicts
0

CVE-2026-45624

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45623

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its

PUBLISHED
Vendor
postcss
Product
postcss
Provider severity
HIGH
Conflicts
1

CVE-2026-45622

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an unauthenticated reflected cross-site scripting (XSS) issue in the public product return form in Vvveb CMS. The customer_order_id POST parameter is inserted into the Order %s not found! error message when the order lookup fails, and that message is rendered in the frontend template without HTML escaping. As a result, attacker-controlled HTML/JavaScript executes in

PUBLISHED
Vendor
givanz
Product
Vvveb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45620

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables unauthenticated user enumeration.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4562

A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
n/a
Product
MacCMS
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-45619

WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS pinning via CURLOPT_RESOLVE, opening DNS-rebinding TOCTOU.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45617

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html filter uses a regex containing four flawed lazy-quantified alternatives, leading to ReDoS via quadratic backtracking. When the input contains many <script, <style, or <!-- opener tokens without matching closers, the V8 regex engine performs O(N²) backtracking, blocking the Node.js event loop. A single ~350 KB request ('<script'.repeat(50000)) stalls the

PUBLISHED
Vendor
harttle
Product
liquidjs
Provider severity
HIGH
Conflicts
0

CVE-2026-45616

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, This vulnerability is fixed in 1.0.8.3.

PUBLISHED
Vendor
givanz
Product
Vvveb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45615

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload for a variable-length, non-negative INTEGER type, the decoder fails to validate the required bytes before extracting the Most Significant Bit (MSB). This forces a precise 1-byte Heap Out-of-Bounds (OOB) Read. Because asn1c generated code is primarily d

PUBLISHED
Vendor
mouse07410
Product
asn1c
Provider severity
HIGH
Conflicts
1

CVE-2026-45614

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of the ECDH shared secret paths, the public key isn't verified to be a point on the correct curve. By passing approximately 30-40 crafted public keys to OP-TEE, the private key can be reconstructed by a normal world attacker. When calling TEE_DeriveKey the public key is provided with full X and Y values,

PUBLISHED
Vendor
OP-TEE
Product
optee_os
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45613

Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bin/format/omf/omf.c. This vulnerability is fixed by commit e6d0937c8a083e23ed76ccfb9f631cdc50c7af47.

PUBLISHED
Vendor
rizinorg
Product
rizin
Provider severity
LOW
Conflicts
0

CVE-2026-45612

rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure is not yet initialized. This issue is fixed in commit 6bf56d3.

PUBLISHED
Vendor
rizinorg
Product
rz-libdemangle
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45610

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getId(), false) on the session-authenticated user, and returns. There is no forbidIfIsUntrustedRequest() call, no isTokenValid() check, no X-CSRF-Token/SameSite enforcement, and no re-authentication step. A cross-origin page that the victim visits while

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45609

mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted URLs for OAuth-related discovery and metadata without verifying if the targets are malicious or internal to the network. This only affects installations with Dynamic Client Registration (DCR) enabled Th

PUBLISHED
Vendor
spring-ai-community
Product
mcp-security
Provider severity
HIGH
Conflicts
0

CVE-2026-45608

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows Server 2025, Windows 10 Version 1809, Windows 11 Version 23H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2016, Windows Server 2012, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45607

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2022, Windows 11 version 26H1, Windows 11 version 23H2, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2016, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-45606

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 R2, Windows Server 2012, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 11 version 23H2, Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2016, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows Server 2022
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45605

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2019, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 10 Version 21H2, Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows 11 version 23H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-45604

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025, Windows 11 version 23H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45603

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2016, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows 11 version 23H2, Windows Server 2022, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-45602

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows Server 2019, Windows 10 Version 1809, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 23H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 22H2, Windows Server 2022
Provider severity
CRITICAL
Conflicts
2

CVE-2026-45601

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2025, Windows 10 Version 1809, Windows 11 Version 23H2, Windows Server 2012, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 version 23H2, Windows Server 2019, Windows Server 2016, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
2

CVE-2026-45600

Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-45599

Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows 11 Version 23H2, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2012
Provider severity
HIGH
Conflicts
1