Common Vulnerabilities and Exposures (CVE)

CVE-2026-57107

Jul 26, 2026 17:16:58 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

CVE-2026-57097

Jul 26, 2026 17:16:58 UTC

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-56185

Jul 26, 2026 17:16:57 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

CVE-2026-56193

Jul 26, 2026 17:16:57 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-54127

Jul 26, 2026 17:16:56 UTC

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

CVE-2026-50694

Jul 26, 2026 17:16:56 UTC

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-56170

Jul 26, 2026 17:16:55 UTC

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVE-2026-56169

Jul 26, 2026 17:16:55 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

CVE-2026-56164

Jul 26, 2026 17:16:54 UTC

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56155

Jul 26, 2026 17:16:53 UTC

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVE-2026-55948

Jul 26, 2026 17:16:53 UTC

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55945

Jul 26, 2026 17:16:52 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

CVE-2026-55899

Jul 26, 2026 17:16:52 UTC

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-54988

Jul 26, 2026 17:16:51 UTC

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-50678

Jul 26, 2026 17:16:51 UTC

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.