Common Vulnerabilities and Exposures (CVE)

CVE-2026-58636

Jul 22, 2026 20:30:17 UTC

Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58635

Jul 22, 2026 20:30:16 UTC

Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVE-2026-58631

Jul 22, 2026 20:30:16 UTC

Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

CVE-2026-58618

Jul 22, 2026 20:30:15 UTC

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-47301

Jul 22, 2026 20:30:15 UTC

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

CVE-2026-58614

Jul 22, 2026 20:30:14 UTC

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-58610

Jul 22, 2026 20:30:14 UTC

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVE-2026-58609

Jul 22, 2026 20:30:13 UTC

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

CVE-2026-58608

Jul 22, 2026 20:30:12 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

CVE-2026-58602

Jul 22, 2026 20:30:12 UTC

Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58601

Jul 22, 2026 20:30:11 UTC

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-56646

Jul 22, 2026 20:30:11 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-56645

Jul 22, 2026 20:30:10 UTC

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58595

Jul 22, 2026 20:30:09 UTC

Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58526

Jul 22, 2026 20:30:08 UTC

Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.