Security Risk Category
Windows Security Risks
Published vulnerability pages connected to Windows. Each page keeps one canonical URL and focused remediation guidance.
216 published Windows risks
Windows risks
Showing 1–36 of 216 published risks.
CVE-2026-11804 Niagara Framework vulnerability
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5.
Updated Jul 24, 2026
CVE-2026-21655 victor vulnerability
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.
Updated Jul 24, 2026
CVE-2026-34496 victor Web vulnerability
Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.
Updated Jul 24, 2026
CVE-2026-15788 BuildKit vulnerability
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.
Updated Jul 21, 2026
CVE-2026-56623 Apache MINA SSHD vulnerability
Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access to git repositories outside of the configured server-side root directory. The path validation applied for CVE-2026-48827 in Apache MINA SSHD 2.18.0 and 3.0.0-M4 was partly ineffective for Servers running on Windows. Applications are affected if they use org.apache.sshd:sshd-git to implement a git server and run on Windows. Applications not using sshd-git or not running on Windows are not affected. Users are advised to upgrade affected applications to Apache MINA SSHD 2.19.0, which fixes the issue. The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M4 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git and run on Windows. Upgrade affected applications to 3.0.0-M5.
Updated Jul 21, 2026
CVE-2026-56647 windows 10 1607 vulnerability
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
Updated Jul 19, 2026
CVE-2026-56648 windows 10 1607 vulnerability
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.
Updated Jul 19, 2026
CVE-2026-56649 windows 10 1607 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.
Updated Jul 19, 2026
CVE-2026-56650 windows 10 1607 vulnerability
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
Updated Jul 19, 2026
CVE-2026-57083 windows 10 1607 vulnerability
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
Updated Jul 19, 2026
CVE-2026-57084 windows 10 1607 vulnerability
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
Updated Jul 19, 2026
CVE-2026-57085 windows 10 1607 vulnerability
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
Updated Jul 19, 2026
CVE-2026-57087 windows 10 1607 vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Updated Jul 19, 2026
CVE-2026-57088 windows 10 1809 vulnerability
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
Updated Jul 19, 2026
CVE-2026-57089 windows 10 1607 vulnerability
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
Updated Jul 19, 2026
CVE-2026-57090 windows 10 1607 vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Updated Jul 19, 2026
CVE-2026-57091 windows 10 1607 vulnerability
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.
Updated Jul 19, 2026
CVE-2026-57092 windows 10 1607 vulnerability
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
Updated Jul 19, 2026
CVE-2026-57093 windows 10 1607 vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Updated Jul 19, 2026
CVE-2026-57094 windows 10 1607 vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Updated Jul 19, 2026
CVE-2026-33842 windows 10 1607 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-34328 windows 10 1809 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-34346 windows 10 1607 vulnerability
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-34348 windows 10 1809 vulnerability
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
Updated Jul 17, 2026
CVE-2026-34349 windows 10 1809 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-40378 windows 10 1607 vulnerability
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
Updated Jul 17, 2026
CVE-2026-40400 windows 10 1607 vulnerability
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
Updated Jul 17, 2026
CVE-2026-40422 windows 10 1607 vulnerability
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-41087 windows 10 1607 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-42900 windows 10 1607 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
Updated Jul 17, 2026
CVE-2026-42975 windows 10 1607 vulnerability
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
Updated Jul 17, 2026
CVE-2026-42982 windows 10 1607 vulnerability
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-42990 windows 10 1607 vulnerability
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
Updated Jul 17, 2026
CVE-2026-44800 windows 11 23h2 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-44806 windows 10 1607 vulnerability
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
Updated Jul 17, 2026
CVE-2026-48564 windows 10 1607 vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
Updated Jul 17, 2026
