CVE Notify
19.7K subscribers
4 photos
288K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-61350
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

🎖@cveNotify
🚨 CVE-2026-61352
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61353
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61356
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61358
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61360
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-61363
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61364
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61365
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61367
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61368
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-61918
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-61920
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-61921
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-61923
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61924
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-61925
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61926
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61928
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

🎖@cveNotify
🚨 CVE-2026-61930
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-61932
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

🎖@cveNotify