CVE Notify
19.7K subscribers
4 photos
286K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-59126
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-59127
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-59133
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.

🎖@cveNotify
🚨 CVE-2026-59134
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61348
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61349
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61353
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61355
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61356
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61359
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61361
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-61363
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61364
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61365
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61367
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61920
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61925
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61926
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61929
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61930
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61932
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

🎖@cveNotify