CVE-2026-58628 Windows Wireless Network Manager Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58629 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58632 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58633 Desktop Window Manager Elevation of Privilege Vulnerability
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58634 Desktop Window Manager Elevation of Privilege Vulnerability
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58637 Windows Client-Side Caching Elevation of Privilege Vulnerability
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58638 Windows Boot Loader Security Feature Bypass Vulnerability
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft
CVE-2026-56181 Windows Network Address Translation (NAT) Spoofing Vulnerability
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Categories: Microsoft
CVE-2026-55121 Microsoft Office Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-58529 Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-55008 Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replace
Information published.
Categories: Microsoft
CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input
Information published.
Categories: Microsoft
CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion
Information published.
Categories: Microsoft
CVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Information published.
Categories: Microsoft
Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft


