CVE-2026-50668 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
Categories: Microsoft
CVE-2026-50669 Windows Telephony Server Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50670 Windows Win32k Elevation of Privilege Vulnerability
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50672 Windows NTFS Elevation of Privilege Vulnerability
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50673 Windows Kernel Elevation of Privilege Vulnerability
Information published.
Categories: Microsoft
CVE-2026-50674 Windows USB Print Driver Elevation of Privilege Vulnerability
Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50676 Windows Media Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50677 Windows Media Elevation of Privilege Vulnerability
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-54115 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50684 Active Directory Federation Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-50679 Windows Search Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50688 Windows Win32k Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50680 Windows Hyper-V Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50681 Windows Secure Channel Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Vulnerability
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-50682 Active Directory Denial of Service Vulnerability
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-50685 Windows DHCP Server Remote Code Execution Vulnerability
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-50683 Windows DHCP Client Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
Categories: Microsoft
CVE-2026-50687 Windows Win32k Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-50686 Windows OLE Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
Categories: Microsoft


