7
CVE-2026-26165 - Windows Shell Elevation of Privilege Vulnerability
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-26162 - Windows OLE Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-26161 - Windows Sensor Data Service Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-26160 - Remote Desktop Licensing Service Elevation of Privilege Vulnerability
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
6.5
CVE-2026-26155 - Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
7.5
CVE-2026-26154 - Windows Server Update Service (WSUS) Tampering Vulnerability
Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
7.1
CVE-2026-26151 - Remote Desktop Spoofing Vulnerability
Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.
9
CVE-2026-26149 - Microsoft Power Apps Security Feature Bypass
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to bypass a security feature over a network.
5.7
CVE-2026-23670 - Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
4.6
CVE-2026-20945 - Microsoft SharePoint Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.