Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 MS:CVE-2026-27918

Windows Shell Elevation of Privilege Vulnerability_MS:CVE-2026-27918

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to eleva...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-27919

Windows UPnP Device Host Elevation of Privilege Vulnerability_MS:CVE-2026-27919

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-26172

Windows Push Notifications Elevation of Privilege Vulnerability_MS:CVE-2026-26172

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized atta...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-26180

Windows Kernel Elevation of Privilege Vulnerability_MS:CVE-2026-26180

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-23666

.NET Framework Denial of Service Vulnerability_MS:CVE-2026-23666

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to de...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-26143

Microsoft PowerShell Security Feature Bypass Vulnerability_MS:CVE-2026-26143

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21637

HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers_MS:CVE-2026-21637

CVE-2026-21637 is regarding a vulnerability in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server whe...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-23657

Microsoft Word Remote Code Execution Vulnerability_MS:CVE-2026-23657

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-33100

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability_MS:CVE-2026-33100

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-33099

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability_MS:CVE-2026-33099

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE