CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-66304 Skype for Business Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
CVE-2026-66306 Skype for Business Information Disclosure Vulnerability
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege Vulnerability
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69341 Windows Image Acquisition Elevation of Privilege Vulnerability
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
CVE-2026-69522 .NET and Visual Studio Remote Code Execution Vulnerability
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-70091 Windows DNS Denial of Service Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.
CVE-2026-69782 Windows DNS Server Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.
CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
CVE-2026-85360 Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-77482 Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-57098 Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-62801 Microsoft PowerShell Security Feature Bypass Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2026-50349 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-67368 Microsoft SQL Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.


