Common Vulnerabilities and Exposures (CVE)

CVE-2026-70461

Aug 13, 2026 17:37:54 UTC

rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attacke...

CVE-2026-62777

Aug 13, 2026 17:37:54 UTC

Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-66804

Aug 13, 2026 17:37:53 UTC

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61359

Aug 13, 2026 17:37:53 UTC

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-62695

Aug 13, 2026 17:37:52 UTC

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-61346

Aug 13, 2026 17:37:52 UTC

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-62869

Aug 13, 2026 17:37:51 UTC

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.

CVE-2026-68823

Aug 13, 2026 17:37:51 UTC

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

CVE-2026-49163

Aug 13, 2026 17:37:50 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

CVE-2026-65667

Aug 13, 2026 17:37:50 UTC

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56162

Aug 13, 2026 17:37:49 UTC

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50516

Aug 13, 2026 17:37:49 UTC

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-59118

Aug 13, 2026 17:37:48 UTC

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56161

Aug 13, 2026 17:37:47 UTC

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

CVE-2026-62830

Aug 13, 2026 17:37:47 UTC

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.