7.8
CVE-2026-21250 - Windows HTTP.sys Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-21251 - Cluster Client Failover (CCF) Elevation of Privilege Vulnerability
Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.
7
CVE-2026-21253 - Mailslot File System Elevation of Privilege Vulnerability
Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
8.8
CVE-2026-21255 - Windows Hyper-V Security Feature Bypass Vulnerability
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
8.8
CVE-2026-21256 - GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
8
CVE-2026-21257 - GitHub Copilot and Visual Studio Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.
5.5
CVE-2026-21261 - Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
7
CVE-2026-21508 - Windows Storage Elevation of Privilege Vulnerability
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
7.5
CVE-2026-21511 - Microsoft Outlook Spoofing Vulnerability
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
8.8
CVE-2026-21516 - GitHub Copilot for Jetbrains Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.