CVE-2026-62801
- EPSS 0.54%
- Veröffentlicht 08.09.2026 17:10:39
- Zuletzt bearbeitet 24.09.2026 23:17:15
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
- EPSS 0.23%
- Veröffentlicht 08.09.2026 17:10:37
- Zuletzt bearbeitet 24.09.2026 23:19:20
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- EPSS 0.25%
- Veröffentlicht 08.09.2026 17:10:31
- Zuletzt bearbeitet 24.09.2026 23:17:38
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
CVE-2026-62744
- EPSS 0.77%
- Veröffentlicht 08.09.2026 17:10:27
- Zuletzt bearbeitet 28.09.2026 17:26:12
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- EPSS 0.25%
- Veröffentlicht 08.09.2026 17:10:26
- Zuletzt bearbeitet 24.09.2026 23:17:14
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-62706
- EPSS 0.56%
- Veröffentlicht 08.09.2026 17:10:26
- Zuletzt bearbeitet 24.09.2026 23:17:14
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- EPSS 0.2%
- Veröffentlicht 19.08.2026 20:58:27
- Zuletzt bearbeitet 08.09.2026 21:18:36
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62738
- EPSS 0.4%
- Veröffentlicht 11.08.2026 17:07:16
- Zuletzt bearbeitet 16.08.2026 19:16:58
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
CVE-2026-56179
- EPSS 0.23%
- Veröffentlicht 11.08.2026 17:07:10
- Zuletzt bearbeitet 13.08.2026 14:17:01
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-65798
- EPSS 0.25%
- Veröffentlicht 11.08.2026 17:06:59
- Zuletzt bearbeitet 17.08.2026 18:56:12
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.