CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
Categories: Microsoft
CVE-2026-58641 .NET Elevation of Privilege Vulnerability
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58651 Microsoft Word Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-59122 Windows Telephony Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-59125 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-59131 AMD Zen Information Disclosure Vulnerability
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-61349 Windows Work Folder Service Elevation of Privilege Vulnerability
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-61355 Windows Sensor Data Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-61364 Windows Remote Desktop Services Elevation of Privilege Vulnerability
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-61365 Windows Remote Desktop Services Elevation of Privilege Vulnerability
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-61357 Application Information Services Elevation of Privilege Vulnerability
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-61358 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-61360 Windows GDI Information Disclosure Vulnerability
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-61926 Windows USB Driver Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft


