CVE-2026-54114 Windows Win32k Elevation of Privilege Vulnerability
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-54996 Windows USB Print Driver Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-54119 Windows Active Directory Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-54997 Windows SMB Information Disclosure Vulnerability
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-54999 Windows TCP/IP Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.
Categories: Microsoft
CVE-2026-55003 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-54995 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-54122 Windows GDI+ Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-55005 Microsoft Exchange Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-55006 Microsoft Exchange Server Elevation of Privilege Vulnerability
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-55009 Microsoft Exchange Server Elevation of Privilege Vulnerability
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50338 Azure Spring Apps Elevation of Privilege Vulnerability
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-55011 Microsoft Defender Remote Code Execution Vulnerability
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-55012 Microsoft Defender Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-50524 .NET Framework Denial of Service Vulnerability
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-55002 Microsoft SQL Server Elevation of Privilege Vulnerability
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-55144 Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
Categories: Microsoft
CVE-2026-50520 Visual Studio Code Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
Categories: Microsoft


