Common Vulnerabilities and Exposures (CVE)

CVE-2026-62728

Aug 27, 2026 14:21:04 UTC

Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-61939

Aug 27, 2026 14:21:03 UTC

Use after free in Winlogon allows an authorized attacker to elevate privileges locally.

CVE-2026-62747

Aug 27, 2026 14:21:03 UTC

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-65787

Aug 27, 2026 14:21:02 UTC

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-62727

Aug 27, 2026 14:21:02 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-54981

Aug 27, 2026 14:21:01 UTC

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-68821

Aug 27, 2026 14:21:01 UTC

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-69836

Aug 27, 2026 14:21:00 UTC

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

CVE-2026-61938

Aug 27, 2026 14:21:00 UTC

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-62771

Aug 27, 2026 14:20:59 UTC

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-62721

Aug 27, 2026 14:20:58 UTC

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

CVE-2026-70335

Aug 27, 2026 14:20:58 UTC

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

CVE-2026-64899

Aug 27, 2026 14:20:57 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-64903

Aug 27, 2026 14:20:57 UTC

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-68801

Aug 27, 2026 14:20:56 UTC

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.