Common Vulnerabilities and Exposures (CVE)

CVE-2026-50345

Aug 6, 2026 20:35:40 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50348

Aug 6, 2026 20:35:39 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50452

Aug 6, 2026 20:35:38 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50390

Aug 6, 2026 20:35:37 UTC

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50377

Aug 6, 2026 20:35:37 UTC

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50357

Aug 6, 2026 20:35:36 UTC

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-50330

Aug 6, 2026 20:35:36 UTC

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50312

Aug 6, 2026 20:35:35 UTC

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-50324

Aug 6, 2026 20:35:35 UTC

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVE-2026-50310

Aug 6, 2026 20:35:34 UTC

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.

CVE-2026-50430

Aug 6, 2026 20:35:34 UTC

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-50339

Aug 6, 2026 20:35:33 UTC

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-50434

Aug 6, 2026 20:35:33 UTC

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-50315

Aug 6, 2026 20:35:32 UTC

Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

CVE-2026-50425

Aug 6, 2026 20:35:31 UTC

Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.