Common Vulnerabilities and Exposures (CVE)

CVE-2026-20870

Feb 13, 2026 20:40:51 UTC

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20868

Feb 13, 2026 20:40:50 UTC

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2026-20867

Feb 13, 2026 20:40:49 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20866

Feb 13, 2026 20:40:49 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20863

Feb 13, 2026 20:40:48 UTC

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20862

Feb 13, 2026 20:40:48 UTC

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

CVE-2026-20861

Feb 13, 2026 20:40:47 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-21219

Feb 13, 2026 20:40:47 UTC

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

CVE-2026-20854

Feb 13, 2026 20:40:46 UTC

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

CVE-2026-20853

Feb 13, 2026 20:40:45 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.

CVE-2026-20849

Feb 13, 2026 20:40:45 UTC

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

CVE-2026-20848

Feb 13, 2026 20:40:44 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-20843

Feb 13, 2026 20:40:44 UTC

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-20960

Feb 13, 2026 20:40:43 UTC

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

CVE-2026-20947

Feb 13, 2026 20:40:42 UTC

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.