CVE-2026-61920
- EPSS 0.48%
- Veröffentlicht 11.08.2026 17:05:50
- Zuletzt bearbeitet 17.08.2026 16:17:16
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.
CVE-2026-61358
- EPSS 3.31%
- Veröffentlicht 11.08.2026 17:05:49
- Zuletzt bearbeitet 16.08.2026 19:16:48
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
CVE-2026-61364
- EPSS 0.28%
- Veröffentlicht 11.08.2026 17:05:48
- Zuletzt bearbeitet 16.08.2026 19:16:49
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61365
- EPSS 0.28%
- Veröffentlicht 11.08.2026 17:05:48
- Zuletzt bearbeitet 16.08.2026 19:16:49
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61355
- EPSS 0.32%
- Veröffentlicht 11.08.2026 17:05:47
- Zuletzt bearbeitet 13.08.2026 14:14:42
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-59131
- EPSS 0.28%
- Veröffentlicht 11.08.2026 17:05:45
- Zuletzt bearbeitet 16.08.2026 19:16:45
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
- EPSS 0.25%
- Veröffentlicht 11.08.2026 17:05:44
- Zuletzt bearbeitet 16.08.2026 19:16:44
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
- EPSS 0.19%
- Veröffentlicht 11.08.2026 17:05:44
- Zuletzt bearbeitet 12.08.2026 17:05:13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
- EPSS 0.19%
- Veröffentlicht 11.08.2026 17:05:43
- Zuletzt bearbeitet 16.08.2026 19:16:44
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-42976
- EPSS 0.22%
- Veröffentlicht 11.08.2026 17:05:40
- Zuletzt bearbeitet 16.08.2026 19:16:41
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.