Security Risk Category
Windows Security Risks — Page 4
Published vulnerability pages connected to Windows. Each page keeps one canonical URL and focused remediation guidance.
216 published Windows risks
Windows risks
Showing 109–144 of 216 published risks.
CVE-2026-50321 windows 10 1607 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-50322 windows 11 24h2 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-50324 windows 10 1607 vulnerability
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Updated Jul 17, 2026
CVE-2026-50326 windows 10 21h2 vulnerability
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-50327 windows 11 24h2 vulnerability
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Updated Jul 17, 2026
CVE-2026-50670 windows 10 1809 vulnerability
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-50673 windows 10 1607 vulnerability
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-50688 windows 10 1607 vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-56643 windows 10 1607 vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-56644 windows 10 1607 vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58529 windows 11 26h1 vulnerability
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
Updated Jul 17, 2026
CVE-2026-58532 windows 10 1607 vulnerability
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58538 windows 10 1809 vulnerability
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58539 windows 10 1607 vulnerability
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Updated Jul 17, 2026
CVE-2026-58540 windows 10 1607 vulnerability
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58541 windows 10 1607 vulnerability
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58542 windows 11 24h2 vulnerability
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
Updated Jul 17, 2026
CVE-2026-58543 windows 11 24h2 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.
Updated Jul 17, 2026
CVE-2026-58544 windows 11 24h2 vulnerability
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58545 windows 10 1607 vulnerability
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
Updated Jul 17, 2026
CVE-2026-58546 windows 10 1607 vulnerability
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Updated Jul 17, 2026
CVE-2026-58547 windows 10 1809 vulnerability
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58594 windows 10 1607 vulnerability
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
Updated Jul 17, 2026
CVE-2026-58613 windows 10 1809 vulnerability
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58619 windows 10 1607 vulnerability
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58626 windows 10 21h2 vulnerability
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
Updated Jul 17, 2026
CVE-2026-58627 windows 10 1607 vulnerability
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Updated Jul 17, 2026
CVE-2026-58628 windows 10 1809 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58629 windows 10 1607 vulnerability
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58632 windows 10 1607 vulnerability
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58637 windows 10 1607 vulnerability
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-58638 windows 10 1809 vulnerability
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
Updated Jul 17, 2026
CVE-2026-50697 in Microsoft Windows
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Updated Jul 16, 2026
CVE-2026-54107 in Microsoft Windows
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
Updated Jul 16, 2026
CVE-2026-54109 in Microsoft Windows
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-54111 in Microsoft Windows
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Updated Jul 16, 2026
