5.5
CVE-2026-20805 - Desktop Window Manager Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
7.7
CVE-2026-20804 - Windows Hello Tampering Vulnerability
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
7.5
CVE-2026-20965 - Windows Admin Center Elevation of Privilege Vulnerability
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
7.2
CVE-2026-20803 - Microsoft SQL Server Elevation of Privilege Vulnerability
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
7.5
CVE-2026-0386 - Windows Deployment Services Remote Code Execution Vulnerability
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
6.4
CVE-2026-21265 - Secure Boot Certificate Expiration Security Feature Bypass Vulnerability
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes relaβ¦
4.4
CVE-2026-20962 - Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
7.5
CVE-2025-37166 - Unexpected shutdown in HPE Instant On Access Points after processing specific packets
A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conducβ¦
7.5
CVE-2025-37165 - Exposure of VLAN information in unintended network interfaces
A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets.
7.8
CVE-2025-10865 - GPU DDK - DevmemIntGetReservationData does not ref the PMR it returns
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improper reference counting on an internal resource caused scenario where potential for use after free was present.