6.5
CVE-2026-24297 - Windows Kerberos Security Feature Bypass Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network.
7
CVE-2026-24296 - Windows Device Association Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
7
CVE-2026-24295 - Windows Device Association Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-24294 - Windows SMB Server Elevation of Privilege Vulnerability
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-24293 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-24292 - Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-24291 - Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-24290 - Windows Projected File System Elevation of Privilege Vulnerability
Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
CVE-2026-24289 - Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
6.8
CVE-2026-24288 - Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.