CVE-2026-20936
- EPSS 0.46%
- Veröffentlicht 13.01.2026 17:57:04
- Zuletzt bearbeitet 30.07.2026 21:17:10
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
- EPSS 0.79%
- Veröffentlicht 13.01.2026 17:57:03
- Zuletzt bearbeitet 30.07.2026 21:17:09
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
CVE-2026-20929
- EPSS 1.16%
- Veröffentlicht 13.01.2026 17:57:02
- Zuletzt bearbeitet 30.07.2026 21:17:09
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
CVE-2026-20872
- EPSS 19.8%
- Veröffentlicht 13.01.2026 17:57:00
- Zuletzt bearbeitet 30.07.2026 21:17:06
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20868
- EPSS 1.39%
- Veröffentlicht 13.01.2026 17:56:58
- Zuletzt bearbeitet 30.07.2026 21:17:06
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2026-20849
- EPSS 1.01%
- Veröffentlicht 13.01.2026 17:56:53
- Zuletzt bearbeitet 30.07.2026 21:17:03
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVE-2026-20843
- EPSS 3.45%
- Veröffentlicht 13.01.2026 17:56:52
- Zuletzt bearbeitet 30.07.2026 21:17:02
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-20940
- EPSS 0.47%
- Veröffentlicht 13.01.2026 17:56:44
- Zuletzt bearbeitet 30.07.2026 21:17:11
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-20927
- EPSS 0.93%
- Veröffentlicht 13.01.2026 17:56:42
- Zuletzt bearbeitet 30.07.2026 21:17:09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
CVE-2026-20925
- EPSS 17.94%
- Veröffentlicht 13.01.2026 17:56:41
- Zuletzt bearbeitet 30.07.2026 21:17:09
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.