Security Risk Category

Windows Security Risks — Page 4

Published vulnerability pages connected to Windows. Each page keeps one canonical URL and focused remediation guidance.

216 published Windows risks

Windows risks

Showing 109–144 of 216 published risks.

highEPSS 0.002

CVE-2026-50321 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50321windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50322 windows 11 24h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50322windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

mediumEPSS 0.008

CVE-2026-50324 windows 10 1607 vulnerability

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVE-2026-50324windowsdenial-of-service

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-50326 windows 10 21h2 vulnerability

Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.

CVE-2026-50326windowsnetwork-securitymemory-corruption

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-50327 windows 11 24h2 vulnerability

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

CVE-2026-50327windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50670 windows 10 1809 vulnerability

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50670linuxwindowsinput-validationinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50673 windows 10 1607 vulnerability

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50673linuxwindowsdenial-of-service

Updated Jul 17, 2026

highEPSS 0.015

CVE-2026-50688 windows 10 1607 vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50688linuxwindowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-56643 windows 10 1607 vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-56643linuxwindowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-56644 windows 10 1607 vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-56644linuxwindowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.009

CVE-2026-58529 windows 11 26h1 vulnerability

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

CVE-2026-58529windowsinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-58532 windows 10 1607 vulnerability

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-58532linuxwindowsinput-validation

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-58538 windows 10 1809 vulnerability

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58538windowsmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.009

CVE-2026-58539 windows 10 1607 vulnerability

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58539windowsinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-58540 windows 10 1607 vulnerability

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-58540windowsauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-58541 windows 10 1607 vulnerability

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2026-58541windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-58542 windows 11 24h2 vulnerability

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-58542windowsmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-58543 windows 11 24h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.

CVE-2026-58543windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-58544 windows 11 24h2 vulnerability

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-58544windowsmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-58545 windows 10 1607 vulnerability

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-58545linuxwindowsauthorization-bypass

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-58546 windows 10 1607 vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58546windows

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-58547 windows 10 1809 vulnerability

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-58547windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.008

CVE-2026-58594 windows 10 1607 vulnerability

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

CVE-2026-58594windowsinput-validation

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-58613 windows 10 1809 vulnerability

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58613windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-58619 windows 10 1607 vulnerability

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58619windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.009

CVE-2026-58626 windows 10 21h2 vulnerability

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-58626windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.009

CVE-2026-58627 windows 10 1607 vulnerability

Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-58627windowsdenial-of-service

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-58628 windows 10 1809 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.

CVE-2026-58628windowsrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-58629 windows 10 1607 vulnerability

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2026-58629windowsmicrosoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-58632 windows 10 1607 vulnerability

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-58632windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-58637 windows 10 1607 vulnerability

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58637windowsmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-58638 windows 10 1809 vulnerability

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

CVE-2026-58638windowscryptography

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-50697 in Microsoft Windows

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50697windowsmicrosoftinformation-disclosureprivilege-escalation

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54107 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54107windowsmicrosoftprivilege-escalationrace-condition

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54109 in Microsoft Windows

Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-54109windowsmicrosoftremote-code-executioninput-validation

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54111 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-54111windowsmicrosoftinformation-disclosurememory-corruption

Updated Jul 16, 2026