Common Vulnerabilities and Exposures (CVE)

CVE-2025-26635

Feb 13, 2026 19:33:02 UTC

Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.

CVE-2025-26639

Feb 13, 2026 19:33:01 UTC

Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-26628

Feb 13, 2026 19:33:00 UTC

Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.

CVE-2025-25002

Feb 13, 2026 19:33:00 UTC

Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.

CVE-2025-25001

Feb 13, 2026 19:32:59 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-25000

Feb 13, 2026 19:32:58 UTC

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2025-24058

Feb 13, 2026 19:32:58 UTC

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2025-21222

Feb 13, 2026 19:32:57 UTC

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

CVE-2025-21221

Feb 13, 2026 19:32:56 UTC

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

CVE-2025-21204

Feb 13, 2026 19:32:55 UTC

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

CVE-2025-21203

Feb 13, 2026 19:32:55 UTC

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVE-2025-21205

Feb 13, 2026 19:32:54 UTC

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

CVE-2025-21191

Feb 13, 2026 19:32:54 UTC

Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

CVE-2025-21197

Feb 13, 2026 19:32:53 UTC

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.

CVE-2025-21174

Feb 13, 2026 19:32:53 UTC

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.