Common Vulnerabilities and Exposures (CVE)

CVE-2026-57095

Aug 24, 2026 21:04:37 UTC

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

CVE-2026-57084

Aug 24, 2026 21:04:36 UTC

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

CVE-2026-57083

Aug 24, 2026 21:04:36 UTC

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

CVE-2026-56649

Aug 24, 2026 21:04:35 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

CVE-2026-56648

Aug 24, 2026 21:04:34 UTC

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-56647

Aug 24, 2026 21:04:34 UTC

Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.

CVE-2026-56194

Aug 24, 2026 21:04:33 UTC

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-54124

Aug 24, 2026 21:04:33 UTC

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

CVE-2026-56644

Aug 24, 2026 21:04:32 UTC

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-56643

Aug 24, 2026 21:04:32 UTC

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-56178

Aug 24, 2026 21:04:31 UTC

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVE-2026-56197

Aug 24, 2026 21:04:30 UTC

Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

CVE-2026-56196

Aug 24, 2026 21:04:30 UTC

Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

CVE-2026-56195

Aug 24, 2026 21:04:29 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-56192

Aug 24, 2026 21:04:28 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.