CVE database
- CVE-2026-69730Critical9.8
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
- CVE-2026-69624Medium6.5
Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.
- CVE-2026-69595Critical9.8
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
- CVE-2026-69576High7.8
Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.
- CVE-2026-69546High8.1
Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
- CVE-2026-69524High8.1
Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
- CVE-2026-69516High7.0
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69439High8.8
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-69401High7.0
Use after free in Audio Video Control Transport Protocol allows an authorized attacker to elevate privileges locally.
- CVE-2026-69395Medium6.5
Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.
- CVE-2026-69380High8.1
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69359High7.8
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-69329High7.5
Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.
- CVE-2026-69304Medium5.9
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- CVE-2026-69275High7.0
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-68895Medium5.5
Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.
- CVE-2026-62895High8.8
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-62813High7.5
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
- CVE-2026-62810High7.8
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-62762Medium6.5
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
This product uses the NVD API but is not endorsed or certified by the NVD.