CVE database
- CVE-2026-85880High7.8
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
- CVE-2026-83941Critical9.9
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
- CVE-2026-81963High7.8
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- CVE-2026-81381Medium6.5
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
- CVE-2026-81380Medium5.3
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
- CVE-2026-81349High7.2
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
- CVE-2026-78510Critical9.8
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-77909High7.7
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
- CVE-2026-73018High8.8
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
- CVE-2026-73014High7.8
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.
- CVE-2026-72986High8.8
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
- CVE-2026-72981High8.1
Use after free in IP Helper allows an unauthorized attacker to execute code over a network.
- CVE-2026-72978Medium5.9
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- CVE-2026-69900High7.8
Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69829Critical9.8
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
- CVE-2026-69821High7.8
Improper encoding or escaping of output in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69809High7.5
Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.
- CVE-2026-69806High7.0
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
- CVE-2026-69805High7.5
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-69731High7.8
Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally.
This product uses the NVD API but is not endorsed or certified by the NVD.