Common Vulnerabilities and Exposures (CVE)

CVE-2026-45607

Aug 13, 2026 20:52:33 UTC

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVE-2026-45606

Aug 13, 2026 20:52:33 UTC

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

CVE-2026-45640

Aug 13, 2026 20:52:32 UTC

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-45639

Aug 13, 2026 20:52:32 UTC

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-45605

Aug 13, 2026 20:52:31 UTC

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-45583

Aug 13, 2026 20:52:31 UTC

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

CVE-2026-45504

Aug 13, 2026 20:52:30 UTC

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-45503

Aug 13, 2026 20:52:30 UTC

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

CVE-2026-45502

Aug 13, 2026 20:52:29 UTC

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

CVE-2026-45501

Aug 13, 2026 20:52:28 UTC

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

CVE-2026-45500

Aug 13, 2026 20:52:28 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-45491

Aug 13, 2026 20:52:27 UTC

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

CVE-2026-45490

Aug 13, 2026 20:52:27 UTC

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

CVE-2026-45487

Aug 13, 2026 20:52:26 UTC

Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVE-2026-45466

Aug 13, 2026 20:52:25 UTC

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.