| Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-33824 | Severity critical Exploited yes |
| Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVE-2026-32157 | Severity high |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an… CVE-2026-26174 | Severity high |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker… CVE-2025-64661 | Severity high |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker… CVE-2025-64658 | Severity high |
| Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a… CVE-2025-62549 | Severity high |
| Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. CVE-2025-62474 | Severity high |
| Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. CVE-2025-62473 | Severity medium |
| Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. CVE-2025-62472 | Severity high |
| Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. CVE-2025-62470 | Severity high |
| Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. CVE-2025-62468 | Severity medium |
| Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. CVE-2025-62467 | Severity high |
| Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. CVE-2025-62466 | Severity high |
| Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. CVE-2025-62464 | Severity high |
| Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. CVE-2025-62463 | Severity medium |
| Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. CVE-2025-62462 | Severity high |
| Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. CVE-2025-62461 | Severity high |
| Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. CVE-2025-62457 | Severity high |
| Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. CVE-2025-62456 | Severity high |
| Microsoft Windows Use After Free Vulnerability CVE-2025-62221 | Severity high Exploited yes |
| Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. CVE-2025-59517 | Severity high |
| Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. CVE-2025-59516 | Severity high |
| Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. CVE-2025-55233 | Severity high |
| Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker… CVE-2025-54100 | Severity high |
| Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability CVE-2025-26633 | Severity high Exploited yes |
| Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability CVE-2025-24993 | Severity high Exploited yes |
| Microsoft Windows Storage Link Following Vulnerability CVE-2025-21391 | Severity high Exploited yes |
| Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability CVE-2025-21335 | Severity high Exploited yes |