Common Vulnerabilities and Exposures (CVE)

CVE-2026-42971

Jul 28, 2026 22:20:03 UTC

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42969

Jul 28, 2026 22:20:02 UTC

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42972

Jul 28, 2026 22:20:01 UTC

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2026-42968

Jul 28, 2026 22:20:00 UTC

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

CVE-2026-42915

Jul 28, 2026 22:20:00 UTC

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.

CVE-2026-42914

Jul 28, 2026 22:19:59 UTC

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

CVE-2026-42912

Jul 28, 2026 22:19:58 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-42913

Jul 28, 2026 22:19:58 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42911

Jul 28, 2026 22:19:57 UTC

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-42916

Jul 28, 2026 22:19:55 UTC

Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-42909

Jul 28, 2026 22:19:50 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42980

Jul 28, 2026 22:19:50 UTC

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-42908

Jul 28, 2026 22:19:49 UTC

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-42907

Jul 28, 2026 22:19:48 UTC

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

CVE-2026-42906

Jul 28, 2026 22:19:48 UTC

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.