Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-20851

Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2085

A security vulnerability has been detected in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulation of the argument ussdValue leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
D-Link
Product
DWR-M921
Provider severity
HIGH
Conflicts
2

CVE-2026-20849

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2008 R2 Service Pack 1, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2016, Windows Server 2022, Windows Server 2008 Service Pack 2 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1607, Windows Server 2012 R2, Windows 11 version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows Server 2025, Windows 11 Version 23H2, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2
Provider severity
HIGH
Conflicts
1

CVE-2026-20848

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2016, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 23H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2019, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-20847

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows Server 2012 R2, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows 10 Version 1607, Windows 11 Version 25H2, Windows 11 version 23H2, Windows Server 2016, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2008 R2 Service Pack 1, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012, Windows Server 2025 (Server Core installation), Windows 10 Version 1809
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20846

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 version 22H3, Windows Server 2019, Windows 11 Version 23H2, Windows Server 2012, Windows Server 2025, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Microsoft Office for Android, Windows Server 2022, Windows Server 2016, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 26H1, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-20844

Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2025, Windows Server 2019, Windows Server 2022, Windows 11 Version 23H2, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 23H2
Provider severity
HIGH
Conflicts
2

CVE-2026-20843

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 Version 23H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2008 Service Pack 2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2012 R2, Windows 11 version 23H2, Windows 11 Version 25H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 10 Version 1809, Windows Server 2008 Service Pack 2, Windows Server 2022, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-20842

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows 11 version 23H2, Windows 10 Version 22H2, Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-20841

Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
Windows Notepad
Provider severity
HIGH
Conflicts
0

CVE-2026-20840

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 10 Version 1809, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2012, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows Server 2016, Windows 11 Version 24H2, Windows Server 2019, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-2084

A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation of the argument langSelection can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
D-Link
Product
DIR-823X
Provider severity
HIGH
Conflicts
2

CVE-2026-20839

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2012 R2, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2008 R2 Service Pack 1, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2025, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows Server 2012, Windows 11 Version 24H2, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20838

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2025, Windows 11 Version 25H2, Windows 11 version 23H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20837

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2019, Windows 11 version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2022, Windows 10 Version 1809, Windows 11 Version 25H2, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-20836

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 10 Version 21H2, Windows Server 2025, Windows 10 Version 1809, Windows 11 version 23H2, Windows Server 2019, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-20835

Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20834

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2008 Service Pack 2, Windows Server 2022, Windows Server 2012, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2008 Service Pack 2 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows Server 2019 (Server Core installation)
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20833

Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 Service Pack 2, Windows Server 2016 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20832

Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 10 Version 1607, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-20831

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2008 Service Pack 2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2008 Service Pack 2, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2022, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2008 R2 Service Pack 1, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows Server 2016, Windows 11 version 23H2, Windows 11 Version 24H2, Windows Server 2012 R2, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2012
Provider severity
HIGH
Conflicts
1

CVE-2026-20830

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-2083

A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
code-projects
Product
Social Networking Site
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-20829

Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 11 version 23H2, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2022, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20828

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2008 Service Pack 2, Windows Server 2012, Windows Server 2022, Windows 11 version 23H2, Windows 10 Version 22H2, Windows Server 2012 R2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2008 R2 Service Pack 1
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20827

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2022, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 11 version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20826

Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 11 version 23H2, Windows 10 Version 21H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2025, Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-20825

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2025, Windows 11 Version 23H2, Windows Server 2019, Windows 11 version 23H2, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20824

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2022, Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows 11 version 23H2, Windows Server 2012, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20823

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 23H2, Windows 10 Version 1607, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2016, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20822

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2019, Windows Server 2022, Windows Server 2025, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2016, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 version 23H2, Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-20821

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2008 Service Pack 2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1809, Windows Server 2008 R2 Service Pack 1, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016, Windows Server 2022, Windows 11 version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2025, Windows 11 Version 23H2, Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20820

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 version 23H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2012, Windows Server 2012 R2, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2019, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2022, Windows Server 2008 Service Pack 2, Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-2082

A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipulation of the argument mac leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.

PUBLISHED
Vendor
D-Link
Product
DIR-823X
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20819

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20818

Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20817

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 11 version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows Server 2022, Windows Server 2025, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-20816

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows Server 2022, Windows Server 2012 (Server Core installation), Windows Server 2008 Service Pack 2 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2016, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2012 R2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-20815

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-20814

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-20812

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 11 version 23H2, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20811

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 11 version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-20810

Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2019, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-2081

A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
D-Link
Product
DIR-823X
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20809

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 23H2, Windows 10 Version 21H2, Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1607, Windows Server 2022, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
2

CVE-2026-20808

Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-20806

Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2019, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 version 22H3, Windows 11 Version 23H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20805

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2022, Windows Server 2019, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012, Windows Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20804

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2025, Windows Server 2016, Windows 11 Version 24H2, Windows 11 version 23H2, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-20803

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SQL Server 2022 for x64-based Systems (CU 22), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2022 (GDR)
Provider severity
HIGH
Conflicts
1