CVE-2026-26168
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:57
- Zuletzt bearbeitet 24.04.2026 17:35:18
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-26159
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:56
- Zuletzt bearbeitet 24.04.2026 19:54:55
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
CVE-2026-26163
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:56
- Zuletzt bearbeitet 24.04.2026 19:30:26
Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-26156
- EPSS 0.14%
- Veröffentlicht 14.04.2026 16:57:55
- Zuletzt bearbeitet 24.04.2026 20:00:49
Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.
- EPSS 0.13%
- Veröffentlicht 14.04.2026 16:57:54
- Zuletzt bearbeitet 24.04.2026 20:05:42
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
CVE-2026-26153
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:54
- Zuletzt bearbeitet 24.04.2026 20:03:39
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-20806
- EPSS 0.12%
- Veröffentlicht 14.04.2026 16:57:51
- Zuletzt bearbeitet 24.04.2026 20:16:21
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
CVE-2026-20928
- EPSS 0.17%
- Veröffentlicht 14.04.2026 16:57:51
- Zuletzt bearbeitet 24.04.2026 20:11:29
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-32212
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:50
- Zuletzt bearbeitet 20.04.2026 14:55:12
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVE-2026-33098
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:46
- Zuletzt bearbeitet 17.04.2026 19:26:07
Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.