Common Vulnerabilities and Exposures (CVE)

CVE-2026-54125

Aug 7, 2026 18:20:00 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50689

Aug 7, 2026 18:20:00 UTC

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

CVE-2026-50686

Aug 7, 2026 18:19:59 UTC

Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.

CVE-2026-50687

Aug 7, 2026 18:19:58 UTC

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50683

Aug 7, 2026 18:19:58 UTC

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2026-50685

Aug 7, 2026 18:19:57 UTC

Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-50682

Aug 7, 2026 18:19:57 UTC

Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.

CVE-2026-54121

Aug 7, 2026 18:19:56 UTC

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

CVE-2026-50681

Aug 7, 2026 18:19:56 UTC

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

CVE-2026-50680

Aug 7, 2026 18:19:55 UTC

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-50688

Aug 7, 2026 18:19:55 UTC

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50679

Aug 7, 2026 18:19:54 UTC

Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-50684

Aug 7, 2026 18:19:54 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.

CVE-2026-54115

Aug 7, 2026 18:19:53 UTC

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

CVE-2026-50677

Aug 7, 2026 18:19:53 UTC

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.