Security Risk Category

Windows Security Risks

Published vulnerability pages connected to Windows. Each page keeps one canonical URL and focused remediation guidance.

216 published Windows risks

Windows risks

Showing 1–36 of 216 published risks.

medium

CVE-2026-11804 Niagara Framework vulnerability

Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5.

CVE-2026-11804linuxwindows

Updated Jul 24, 2026

high

CVE-2026-21655 victor vulnerability

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.

CVE-2026-21655windowsunsafe-deserialization

Updated Jul 24, 2026

high

CVE-2026-34496 victor Web vulnerability

Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.

CVE-2026-34496windows

Updated Jul 24, 2026

medium

CVE-2026-15788 BuildKit vulnerability

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.

CVE-2026-15788windowspath-traversal

Updated Jul 21, 2026

high

CVE-2026-56623 Apache MINA SSHD vulnerability

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access to git repositories outside of the configured server-side root directory. The path validation applied for CVE-2026-48827 in Apache MINA SSHD 2.18.0 and 3.0.0-M4 was partly ineffective for Servers running on Windows. Applications are affected if they use org.apache.sshd:sshd-git to implement a git server and run on Windows. Applications not using sshd-git or not running on Windows are not affected. Users are advised to upgrade affected applications to Apache MINA SSHD 2.19.0, which fixes the issue. The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M4 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git and run on Windows. Upgrade affected applications to 3.0.0-M5.

CVE-2026-56623javawindowsnetwork-securitypath-traversal

Updated Jul 21, 2026

highEPSS 0.009

CVE-2026-56647 windows 10 1607 vulnerability

Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.

CVE-2026-56647windowsinput-validation

Updated Jul 19, 2026

highEPSS 0.005

CVE-2026-56648 windows 10 1607 vulnerability

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-56648windowsmemory-corruptionrace-condition

Updated Jul 19, 2026

mediumEPSS 0.007

CVE-2026-56649 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

CVE-2026-56649windowsmemory-corruptionrace-condition

Updated Jul 19, 2026

highEPSS 0.003

CVE-2026-56650 windows 10 1607 vulnerability

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

CVE-2026-56650windowsmemory-corruption

Updated Jul 19, 2026

mediumEPSS 0.005

CVE-2026-57083 windows 10 1607 vulnerability

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

CVE-2026-57083windowsmicrosoft

Updated Jul 19, 2026

mediumEPSS 0.005

CVE-2026-57084 windows 10 1607 vulnerability

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

CVE-2026-57084windows

Updated Jul 19, 2026

mediumEPSS 0.003

CVE-2026-57085 windows 10 1607 vulnerability

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

CVE-2026-57085windowsinformation-disclosure

Updated Jul 19, 2026

highEPSS 0.008

CVE-2026-57087 windows 10 1607 vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57087windowsmicrosoftmemory-corruption

Updated Jul 19, 2026

highEPSS 0.003

CVE-2026-57088 windows 10 1809 vulnerability

Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.

CVE-2026-57088windowsauthorization-bypass

Updated Jul 19, 2026

highEPSS 0.006

CVE-2026-57089 windows 10 1607 vulnerability

Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.

CVE-2026-57089windowsmemory-corruption

Updated Jul 19, 2026

highEPSS 0.008

CVE-2026-57090 windows 10 1607 vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57090windowsmicrosoftmemory-corruption

Updated Jul 19, 2026

highEPSS 0.004

CVE-2026-57091 windows 10 1607 vulnerability

Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-57091windowsmemory-corruption

Updated Jul 19, 2026

criticalEPSS 0.010

CVE-2026-57092 windows 10 1607 vulnerability

Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.

CVE-2026-57092windowsmemory-corruption

Updated Jul 19, 2026

highEPSS 0.003

CVE-2026-57093 windows 10 1607 vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-57093windowsmemory-corruption

Updated Jul 19, 2026

highEPSS 0.008

CVE-2026-57094 windows 10 1607 vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57094windowsmicrosoftinformation-disclosurememory-corruption

Updated Jul 19, 2026

medium

CVE-2026-33842 windows 10 1607 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-33842windowsinformation-disclosure

Updated Jul 17, 2026

medium

CVE-2026-34328 windows 10 1809 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

CVE-2026-34328windowsinformation-disclosure

Updated Jul 17, 2026

medium

CVE-2026-34346 windows 10 1607 vulnerability

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

CVE-2026-34346windowsinformation-disclosure

Updated Jul 17, 2026

medium

CVE-2026-34348 windows 10 1809 vulnerability

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

CVE-2026-34348windows

Updated Jul 17, 2026

medium

CVE-2026-34349 windows 10 1809 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

CVE-2026-34349windowsinformation-disclosure

Updated Jul 17, 2026

high

CVE-2026-40378 windows 10 1607 vulnerability

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVE-2026-40378windows

Updated Jul 17, 2026

highEPSS 0.006

CVE-2026-40400 windows 10 1607 vulnerability

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

CVE-2026-40400windowspath-traversal

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-40422 windows 10 1607 vulnerability

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-40422windows

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-41087 windows 10 1607 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-41087windowsinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-42900 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-42900windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-42975 windows 10 1607 vulnerability

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-42975windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-42982 windows 10 1607 vulnerability

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-42982linuxwindows

Updated Jul 17, 2026

criticalEPSS 0.007

CVE-2026-42990 windows 10 1607 vulnerability

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

CVE-2026-42990windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-44800 windows 11 23h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-44800windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

mediumEPSS 0.008

CVE-2026-44806 windows 10 1607 vulnerability

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

CVE-2026-44806windowsdenial-of-service

Updated Jul 17, 2026

highEPSS 0.008

CVE-2026-48564 windows 10 1607 vulnerability

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-48564windowsmemory-corruption

Updated Jul 17, 2026