Common Vulnerabilities and Exposures (CVE)

CVE-2026-54115

Sep 4, 2026 22:15:33 UTC

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

CVE-2026-50677

Sep 4, 2026 22:15:33 UTC

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50676

Sep 4, 2026 22:15:32 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50674

Sep 4, 2026 22:15:32 UTC

Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50673

Sep 4, 2026 22:15:31 UTC

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50672

Sep 4, 2026 22:15:30 UTC

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50670

Sep 4, 2026 22:15:30 UTC

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50669

Sep 4, 2026 22:15:29 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50668

Sep 4, 2026 22:15:29 UTC

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-50667

Sep 4, 2026 22:15:28 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50666

Sep 4, 2026 22:15:28 UTC

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.

CVE-2026-50661

Sep 4, 2026 22:15:27 UTC

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-50659

Sep 4, 2026 22:15:27 UTC

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

CVE-2026-50658

Sep 4, 2026 22:15:26 UTC

Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVE-2026-50657

Sep 4, 2026 22:15:26 UTC

Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.