CVE Notify
19.7K subscribers
4 photos
286K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-43606
Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.

🎖@cveNotify
🚨 CVE-2026-48440
ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.

🎖@cveNotify
🚨 CVE-2026-50472
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-54984
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-57104
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.

🎖@cveNotify
🚨 CVE-2026-58641
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-59113
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-59122
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-59124
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-59125
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-59134
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61352
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61353
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61358
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61359
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61363
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61364
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61365
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61918
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-61920
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61925
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify