Security Risk Category

Windows Security Risks — Page 5

Published vulnerability pages connected to Windows. Each page keeps one canonical URL and focused remediation guidance.

216 published Windows risks

Windows risks

Showing 145–180 of 216 published risks.

highEPSS 0.002

CVE-2026-54112 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54112windowsmicrosoftmemory-corruptionprivilege-escalation

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-58633 in Microsoft Windows

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58633windowsmicrosoftmemory-corruptionprivilege-escalation

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-58634 in Microsoft Windows

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58634windowsmicrosoftmemory-corruptionprivilege-escalation

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-15767 in Google Chrome

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)

CVE-2026-15767browserwindowsremote-code-executionmemory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15771 in Google Chrome

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15771browserwindowsinput-validationinformation-disclosure

Updated Jul 16, 2026

criticalEPSS 0.003

CVE-2026-15773 in Google Chrome

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15773browserwindowsmemory-corruptionprivilege-escalation

Updated Jul 16, 2026

high

CVE-2026-40952 in Absolute Secure Access

CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.

CVE-2026-40952windowsnetwork-securityprivilege-escalation

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-44040 UltraVNC Weak RNG Authentication Challenge

UltraVNC through 1.8.2.2 uses a cryptographically weak pseudo-random number generator to produce VNC authentication challenge bytes. In rfb/vncauth.c:119-129, the vncRandomBytes() function seeds libc rand() with time(0) + getpid() + rand() and generates a 16-byte challenge. The combined seed space is approximately 31 bits (libc rand() internal state) and is entirely determined by publicly-observable values (wall-clock time and process ID). An attacker who can observe the authentication exchange can enumerate the seed space and predict the challenge within seconds, enabling forgery or offline brute-forcing of responses. Note: on Windows, the active code path may use vncEncryptBytes2.cpp which calls CryptGenRandom; reachability on shipped Windows binaries requires compile-graph verification and is under investigation.

CVE-2026-44040windowsnetwork-securityauthentication-bypasscryptography

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-57211 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management...

CVE-2026-57211windowsnetwork-securitypath-traversalssrf

Updated Jul 15, 2026

criticalEPSS 0.197

CVE-2026-50522 in Microsoft SharePoint Server

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVE-2026-50522windowsmicrosoftweb-applicationremote-code-execution

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-54108 in Microsoft SharePoint Server

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-54108windowsmicrosoftweb-applicationpath-traversal

Updated Jul 15, 2026

criticalEPSS 0.013

CVE-2026-58644 in Microsoft SharePoint Server

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVE-2026-58644windowsmicrosoftweb-applicationremote-code-execution

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55016 in Microsoft SharePoint Server

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-55016windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-55019 in Microsoft SharePoint Server

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-55019windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55020 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55020windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-55021 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55021windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-55030 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55030windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-55034 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55034windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55135 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55135windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-55947 in Microsoft Excel / Microsoft 365 Apps

Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.

CVE-2026-55947windowsmicrosoftremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-55949 in Microsoft Excel / Microsoft 365 Apps

Microsoft Excel has an uninitialized resource issue that can let an attacker run code when a user opens a malicious file.

CVE-2026-55949windowsmicrosoftremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-56156 in Microsoft Excel / Microsoft 365 Apps

Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.

CVE-2026-56156windowsmicrosoftremote-code-executionmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56157 in Microsoft SharePoint Server

Microsoft SharePoint Server has an access control issue that can let an authorized attacker spoof content over the network.

CVE-2026-56157windowsmicrosoftweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.008

CVE-2026-58277 in Microsoft SharePoint Server

Microsoft SharePoint Server has an authorization issue that can let an authorized attacker gain higher privileges over the network.

CVE-2026-58277windowsmicrosoftweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-58596 in Microsoft Edge Chromium

Microsoft Edge Chromium has an untrusted pointer dereference issue that can let an attacker gain elevated access over the network.

CVE-2026-58596browserlinuxwindowsmicrosoft

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-8085 in Rockwell Automation Arena Simulation

Arena Simulation has an out-of-bounds write issue in model.exe that can run code if a user opens a malicious file.

CVE-2026-8085windowsindustrial-controlremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-8312 in Rockwell Automation Arena Simulation

Arena Simulation has an out-of-bounds write issue in expmt.exe that can run code if a user opens a malicious file.

CVE-2026-8312windowsindustrial-controlremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-8313 in Rockwell Automation Arena Simulation

Arena Simulation has an out-of-bounds write issue in linker.exe that can run code if a user opens a malicious file.

CVE-2026-8313windowsindustrial-controlremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-8314 in Rockwell Automation Arena Simulation

Arena Simulation has an out-of-bounds write issue in siman.exe that can run code if a user opens a malicious file.

CVE-2026-8314windowsindustrial-controlremote-code-executionmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-47969 in Adobe Audition

Adobe Audition has an out-of-bounds read issue that can expose memory if a user opens a malicious file.

CVE-2026-47969windowsinformation-disclosurememory-corruption

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-48309 in Adobe Audition

Adobe Audition has an out-of-bounds write issue that can run code if a user opens a malicious file.

CVE-2026-48309windowsremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-48365 in Adobe Audition

Adobe Audition has an out-of-bounds write issue that can run code if a user opens a malicious file.

CVE-2026-48365windowsremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-48368 in Adobe Audition

Adobe Audition has an out-of-bounds write issue that can run code if a user opens a malicious file.

CVE-2026-48368windowsremote-code-executionmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-55054 in Microsoft Excel and Microsoft 365 Apps

Microsoft Excel has an out-of-bounds read issue that can disclose information when a user opens a crafted file.

CVE-2026-55054windowsmicrosoftinformation-disclosurememory-corruption

Updated Jul 15, 2026

criticalEPSS 0.010

CVE-2026-58126 in PACSgear PACS Scan

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remote code execution as NT Authority\SYSTEM upon service restart.

CVE-2026-58126dotnetwindowsnetwork-securityremote-code-execution

Updated Jul 15, 2026

criticalEPSS 0.010

CVE-2026-58127 in PACSgear MediaWriter

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods, an unauthenticated remote attacker can read and write arbitrary files on the host filesystem. The ObjectURIs are identical across all installations by default. Chaining the arbitrary file write primitive with DLL hijacking opportunities in the MediaWriter service (which runs as NT Authority\\SYSTEM and loads missing DLLs such as CRYPTBASE.DLL from the application directory) enables unauthenticated remote code execution as SYSTEM upon service restart.

CVE-2026-58127dotnetwindowsnetwork-securityremote-code-execution

Updated Jul 15, 2026