Common Vulnerabilities and Exposures (CVE)

CVE-2026-58640

Sep 4, 2026 22:12:45 UTC

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-58636

Sep 4, 2026 22:12:44 UTC

Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58635

Sep 4, 2026 22:12:44 UTC

Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVE-2026-58631

Sep 4, 2026 22:12:43 UTC

Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

CVE-2026-58618

Sep 4, 2026 22:12:43 UTC

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-47301

Sep 4, 2026 22:12:42 UTC

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

CVE-2026-58614

Sep 4, 2026 22:12:41 UTC

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-58610

Sep 4, 2026 22:12:41 UTC

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVE-2026-58609

Sep 4, 2026 22:12:40 UTC

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

CVE-2026-58608

Sep 4, 2026 22:12:40 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

CVE-2026-58602

Sep 4, 2026 22:12:39 UTC

Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58601

Sep 4, 2026 22:12:37 UTC

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-56646

Sep 4, 2026 22:12:37 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-56645

Sep 4, 2026 22:12:36 UTC

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-50522

Sep 4, 2026 22:12:36 UTC

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.