Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7 MS:CVE-2026-34345

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability_MS:CVE-2026-34345

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-35415

Windows Storage Spaces Controller Elevation of Privilege Vulnerability_MS:CVE-2026-35415

Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 6.2 MS:CVE-2026-40380

Windows Volume Manager Extension Driver Remote Code Execution Vulnerability_MS:CVE-2026-40380

Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-40397

Windows Common Log File System Driver Elevation of Privilege Vulnerability_MS:CVE-2026-40397

Integer underflow (wrap or wraparound) in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-41086

Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability_MS:CVE-2026-41086

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

N/A N/A MSCVE
HIGH 7.1 MS:CVE-2026-40401

Windows TCP/IP Denial of Service Vulnerability_MS:CVE-2026-40401

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-40381

Azure Connected Machine Agent Elevation of Privilege Vulnerability_MS:CVE-2026-40381

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-40369

Windows Kernel Elevation of Privilege Vulnerability_MS:CVE-2026-40369

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-40382

Windows Telephony Service Elevation of Privilege Vulnerability_MS:CVE-2026-40382

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 4.4 MS:CVE-2026-32209

Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability_MS:CVE-2026-32209

Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.

N/A N/A MSCVE