Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 MS:CVE-2026-20922

Windows NTFS Remote Code Execution Vulnerability_MS:CVE-2026-20922

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-20946

Microsoft Excel Remote Code Execution Vulnerability_MS:CVE-2026-20946

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-20951

Microsoft SharePoint Server Remote Code Execution Vulnerability_MS:CVE-2026-20951

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
MEDIUM 6.2 MS:CVE-2026-20935

Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability_MS:CVE-2026-20935

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-20836

DirectX Graphics Kernel Elevation of Privilege Vulnerability_MS:CVE-2026-20836

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to ele...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-20868

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability_MS:CVE-2026-20868

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-20866

Windows Management Services Elevation of Privilege Vulnerability_MS:CVE-2026-20866

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized att...

N/A N/A MSCVE
HIGH 8.1 MS:CVE-2026-20856

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability_MS:CVE-2026-20856

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
MEDIUM 4.6 MS:CVE-2026-20828

Windows rndismp6.sys Information Disclosure Vulnerability_MS:CVE-2026-20828

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.

N/A N/A MSCVE
MEDIUM 4.4 MS:CVE-2026-20825

Windows Hyper-V Information Disclosure Vulnerability_MS:CVE-2026-20825

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

N/A N/A MSCVE