CVE-2026-80077 Remote Desktop Client Remote Code Execution Vulnerability
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-80075 Windows Work Folders Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.
CVE-2026-80083 Windows Hyper-V Remote Code Execution Vulnerability
Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.
CVE-2026-80093 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-80097 Microsoft Authenticator Elevation of Privilege Vulnerability
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.
CVE-2026-81349 Azure HDInsight Ambari Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.
CVE-2026-81356 Visual Studio Code Security Feature Bypass Vulnerability
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81357 Visual Studio Code Security Feature Bypass Vulnerability
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81376 Visual Studio Code Security Feature Bypass Vulnerability
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81377 Visual Studio Code Tampering Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
CVE-2026-81378 Visual Studio Code Security Feature Bypass Vulnerability
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81379 Visual Studio Code Security Feature Bypass Vulnerability
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81380 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-81381 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-70065 Windows DHCP Server Denial of Service Vulnerability
Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-83942 Windows Kernel Elevation of Privilege Vulnerability
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-83952 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-69989 Windows DNS Server Remote Code Execution Vulnerability
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
CVE-2026-69827 Windows DNS Server Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.


