CVE-2026-26159
- EPSS 0.26%
- Veröffentlicht 14.04.2026 16:57:56
- Zuletzt bearbeitet 24.04.2026 19:54:55
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
CVE-2026-26163
- EPSS 0.3%
- Veröffentlicht 14.04.2026 16:57:56
- Zuletzt bearbeitet 24.04.2026 19:30:26
Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- EPSS 0.23%
- Veröffentlicht 14.04.2026 16:57:54
- Zuletzt bearbeitet 24.04.2026 20:05:42
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
CVE-2026-32212
- EPSS 0.31%
- Veröffentlicht 14.04.2026 16:57:50
- Zuletzt bearbeitet 20.04.2026 14:55:12
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
- EPSS 0.54%
- Veröffentlicht 14.04.2026 16:57:50
- Zuletzt bearbeitet 24.07.2026 22:10:00
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
CVE-2026-32217
- EPSS 0.42%
- Veröffentlicht 14.04.2026 16:57:38
- Zuletzt bearbeitet 20.04.2026 14:34:17
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-32202
- EPSS 63.69%
- Veröffentlicht 14.04.2026 16:57:36
- Zuletzt bearbeitet 14.08.2026 17:17:51
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32183
- EPSS 0.62%
- Veröffentlicht 14.04.2026 16:57:32
- Zuletzt bearbeitet 20.04.2026 16:40:00
Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally.
CVE-2026-32157
- EPSS 0.78%
- Veröffentlicht 14.04.2026 16:57:26
- Zuletzt bearbeitet 25.09.2026 18:17:19
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-32156
- EPSS 0.29%
- Veröffentlicht 14.04.2026 16:57:25
- Zuletzt bearbeitet 23.04.2026 14:51:17
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.