CVE-2026-70290 Win32k Information Disclosure Vulnerability
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
CVE-2026-83991 Windows Cloud Files Mini Filter Driver Tampering Vulnerability
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
CVE-2026-83996 Windows Error Reporting Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2026-83998 Remote Desktop Client Remote Code Execution Vulnerability
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-83999 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
CVE-2026-84001 Windows Key Distribution Center Denial of Service Vulnerability
Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
CVE-2026-85877 Windows Print Spooler Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-56177 Windows Server Elevation of Privilege Vulnerability
Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
CVE-2026-56198 Microsoft Trace Data Helper Elevation of Privilege Vulnerability
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
CVE-2026-58611 Xbox Gaming Services Elevation of Privilege Vulnerability
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
CVE-2026-62810 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability
CVE-2026-62759 Windows Netlogon Spoofing Vulnerability
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-62762 Windows Active Directory Domain Services Denial of Service Vulnerability
CVE-2026-62813 Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-62697 Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-56172 Windows VHD miniport driver Elevation of Privilege Vulnerability
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
CVE-2026-66814 Microsoft SQL Server Elevation of Privilege Vulnerability
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-66816 Microsoft SQL Server Security Feature Bypass Vulnerability
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-66818 Microsoft SQL Server Elevation of Privilege Vulnerability
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.


