CVE Notify
19.7K subscribers
4 photos
286K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-59122
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-59124
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-59125
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-59134
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61352
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61353
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61358
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61359
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61363
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61364
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61365
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61918
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-61920
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61925
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61926
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61929
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61932
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61937
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61938
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-62690
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-62692
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify