Common Vulnerabilities and Exposures (CVE)

CVE-2026-20861

Feb 26, 2026 15:04:22 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-1862

Feb 26, 2026 15:04:22 UTC

Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2026-20863

Feb 26, 2026 15:04:22 UTC

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-1580

Feb 26, 2026 15:04:22 UTC

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-...

CVE-2026-20866

Feb 26, 2026 15:04:22 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-24512

Feb 26, 2026 15:04:22 UTC

A security issue was discovered in ingress-nginx cthe `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclo...

CVE-2026-20867

Feb 26, 2026 15:04:21 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20979

Feb 26, 2026 15:04:21 UTC

Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.

CVE-2026-20868

Feb 26, 2026 15:04:21 UTC

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2026-20983

Feb 26, 2026 15:04:21 UTC

Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.

CVE-2026-20870

Feb 26, 2026 15:04:21 UTC

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2025-14740

Feb 26, 2026 15:04:21 UTC

Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\DockerDesktop directory. The installer creates this directory without proper ownership verificati...

CVE-2026-20871

Feb 26, 2026 15:04:20 UTC

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-0659

Feb 26, 2026 15:04:20 UTC

A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of ...

CVE-2026-20873

Feb 26, 2026 15:04:20 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.