CVE Notify
19.4K subscribers
4 photos
223K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-50297
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50298
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.

🎖@cveNotify
🚨 CVE-2026-50299
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.

🎖@cveNotify
🚨 CVE-2026-50300
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-50303
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.

🎖@cveNotify
🚨 CVE-2026-50308
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-50311
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50316
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-50323
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50325
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50333
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50342
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50351
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50354
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50356
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50364
Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50381
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-50384
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-50652
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

🎖@cveNotify
🚨 CVE-2026-50653
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

🎖@cveNotify
🚨 CVE-2026-50694
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

🎖@cveNotify