| Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. CVE-2026-85360 | Severity high |
| Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network. CVE-2026-84001 | Severity high |
| Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally. CVE-2026-84000 | Severity high |
| Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVE-2026-83998 | Severity high |
| Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. CVE-2026-83997 | Severity high |
| Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally. CVE-2026-83996 | Severity high |
| Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. CVE-2026-83995 | Severity high |
| Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. CVE-2026-83992 | Severity high |
| Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. CVE-2026-83990 | Severity high |
| Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network. CVE-2026-83989 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83988 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83987 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83985 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83983 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83982 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83981 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83980 | Severity high |
| Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83979 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83978 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83977 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83976 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83974 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83973 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83972 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83971 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83970 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83969 | Severity high |
| Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83968 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83967 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83955 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-83954 | Severity high |
| Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally. CVE-2026-83942 | Severity high |
| Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. CVE-2026-83940 | Severity high |
| Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. CVE-2026-83501 | Severity medium |
| Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges… CVE-2026-83498 | Severity high |
| Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally. CVE-2026-81355 | Severity high |
| Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. CVE-2026-81354 | Severity high |
| Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network. CVE-2026-81352 | Severity high |
| Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. CVE-2026-80096 | Severity high |
| Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. CVE-2026-80093 | Severity high |
| Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally. CVE-2026-80083 | Severity high |
| Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to… CVE-2026-78516 | Severity medium |
| Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack. CVE-2026-78508 | Severity medium |
| Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack. CVE-2026-78455 | Severity medium |
| Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally. CVE-2026-78454 | Severity medium |
| Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information… CVE-2026-78453 | Severity medium |
| Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical… CVE-2026-78452 | Severity medium |
| Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a… CVE-2026-78451 | Severity medium |
| Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. CVE-2026-78449 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-78448 | Severity high |
| Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. CVE-2026-78446 | Severity medium |
| Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. CVE-2026-77905 | Severity high |
| Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. CVE-2026-77904 | Severity high |
| Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network. CVE-2026-77896 | Severity high |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized… CVE-2026-77894 | Severity high |
| No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack. CVE-2026-77892 | Severity medium |
| Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. CVE-2026-77504 | Severity high |
| Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. CVE-2026-77503 | Severity high |
| Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally. CVE-2026-77500 | Severity high |
| Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. CVE-2026-77495 | Severity high |
| Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. CVE-2026-77493 | Severity critical |
| Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. CVE-2026-77492 | Severity medium |
| Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. CVE-2026-77491 | Severity medium |
| Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-77489 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-73026 | Severity high |
| Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally. CVE-2026-73024 | Severity high |
| Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. CVE-2026-73023 | Severity high |
| Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. CVE-2026-73022 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-73021 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-73020 | Severity high |
| Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network. CVE-2026-73019 | Severity medium |
| Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. CVE-2026-73018 | Severity high |
| Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. CVE-2026-73017 | Severity high |
| Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. CVE-2026-73016 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-73015 | Severity high |
| Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally. CVE-2026-73014 | Severity high |
| Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. CVE-2026-73013 | Severity high |
| Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network. CVE-2026-73012 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-73011 | Severity high |
| Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. CVE-2026-73009 | Severity critical |
| Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose… CVE-2026-73008 | Severity medium |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-73007 | Severity high |
| Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. CVE-2026-73006 | Severity high |
| Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. CVE-2026-73005 | Severity high |
| Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally. CVE-2026-73004 | Severity medium |
| Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. CVE-2026-73003 | Severity high |
| Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-73002 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-73001 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-73000 | Severity high |
| Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. CVE-2026-72999 | Severity medium |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-72997 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-72996 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-72995 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-72994 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-72993 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-72992 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-72991 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-72990 | Severity high |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. CVE-2026-72988 | Severity high |
| Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. CVE-2026-72986 | Severity high |