Common Vulnerabilities and Exposures (CVE)

CVE-2026-54981

Aug 21, 2026 23:10:22 UTC

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-68821

Aug 21, 2026 23:10:22 UTC

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-69836

Aug 21, 2026 23:10:21 UTC

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

CVE-2026-61938

Aug 21, 2026 23:10:21 UTC

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-62771

Aug 21, 2026 23:10:20 UTC

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-62721

Aug 21, 2026 23:10:19 UTC

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

CVE-2026-70335

Aug 21, 2026 23:10:19 UTC

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

CVE-2026-64899

Aug 21, 2026 23:10:18 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-64903

Aug 21, 2026 23:10:18 UTC

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-68801

Aug 21, 2026 23:10:17 UTC

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-62755

Aug 21, 2026 23:10:17 UTC

Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

CVE-2026-62703

Aug 21, 2026 23:10:16 UTC

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVE-2026-65786

Aug 21, 2026 23:10:16 UTC

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-61363

Aug 21, 2026 23:10:15 UTC

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-62728

Aug 21, 2026 23:10:15 UTC

Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.