Common Vulnerabilities and Exposures (CVE)

CVE-2026-50670

Jul 30, 2026 20:25:44 UTC

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50669

Jul 30, 2026 20:25:44 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50668

Jul 30, 2026 20:25:43 UTC

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-50667

Jul 30, 2026 20:25:43 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50666

Jul 30, 2026 20:25:42 UTC

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.

CVE-2026-50661

Jul 30, 2026 20:25:41 UTC

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-50659

Jul 30, 2026 20:25:41 UTC

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

CVE-2026-50658

Jul 30, 2026 20:25:40 UTC

Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVE-2026-50657

Jul 30, 2026 20:25:40 UTC

Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.

CVE-2026-50655

Jul 30, 2026 20:25:39 UTC

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-50651

Jul 30, 2026 20:25:39 UTC

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

CVE-2026-50650

Jul 30, 2026 20:25:38 UTC

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

CVE-2026-50649

Jul 30, 2026 20:25:38 UTC

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

CVE-2026-50648

Jul 30, 2026 20:25:37 UTC

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

CVE-2026-50647

Jul 30, 2026 20:25:36 UTC

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.