CVE Notify
19.5K subscribers
4 photos
238K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-58610
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-50348
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.

🎖@cveNotify
🚨 CVE-2026-50352
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-50353
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50357
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-50358
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50359
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50360
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

🎖@cveNotify
🚨 CVE-2026-50361
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50386
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-50387
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50388
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-50389
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-50401
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-50402
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50403
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50421
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50422
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50424
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.

🎖@cveNotify
🚨 CVE-2026-57095
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-57096
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify