Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 MS:CVE-2026-20854

Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability_MS:CVE-2026-20854

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-20929

Windows HTTP.sys Elevation of Privilege Vulnerability_MS:CVE-2026-20929

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-20922

Windows NTFS Remote Code Execution Vulnerability_MS:CVE-2026-20922

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-20946

Microsoft Excel Remote Code Execution Vulnerability_MS:CVE-2026-20946

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-20951

Microsoft SharePoint Server Remote Code Execution Vulnerability_MS:CVE-2026-20951

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
MEDIUM 6.2 MS:CVE-2026-20935

Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability_MS:CVE-2026-20935

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-20836

DirectX Graphics Kernel Elevation of Privilege Vulnerability_MS:CVE-2026-20836

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to ele...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-20868

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability_MS:CVE-2026-20868

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-20866

Windows Management Services Elevation of Privilege Vulnerability_MS:CVE-2026-20866

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized att...

N/A N/A MSCVE
HIGH 8.1 MS:CVE-2026-20856

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability_MS:CVE-2026-20856

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE