Security Risk Category

Windows Security Risks — Page 6

Published vulnerability pages connected to Windows. Each page keeps one canonical URL and focused remediation guidance.

216 published Windows risks

Windows risks

Showing 181–216 of 216 published risks.

high

CVE-2026-59841 in FortiSIEM Windows Agent

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>

CVE-2026-59841windowsnetwork-securityprivilege-escalation

Updated Jul 15, 2026

criticalCISA KEV

CVE-2026-56155 in Active Directory Federation Services

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

CVE-2026-56155windowsmicrosoftauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-41121 in Dell Device Management Agent

Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

CVE-2026-41121windowspath-traversalfile-writeprivilege-escalation

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-14384 in Google Chrome ANGLE

Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14384browserwindowsinformation-disclosurememory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14391 in Google Chrome ANGLE

Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14391browserwindowsinput-validationinformation-disclosure

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14402 in Google Chrome ANGLE

Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14402browserwindowsinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.001

CVE-2026-38972 Notepad3 Vulnerability

Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application calls LoadLibrary(L"MSFTEDIT.DLL") with a bare DLL name, which allows a local attacker to place a malicious MSFTEDIT.DLL in the application directory or another preferred DLL search location and achieve arbitrary code execution in the context of the user when the About dialog is opened.

CVE-2026-38972windowssupply-chainremote-code-executionpath-traversal

Updated Jul 14, 2026

high

CVE-2026-13079 mobile vpn with ssl vulnerability

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.

CVE-2026-13079windowsnetwork-securityprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.007

CVE-2026-9181 arcgis server vulnerability

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full administrative access to ArcGIS Server, with high impact to confidentiality, integrity, and availability. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

CVE-2026-9181linuxwindowscloud-securityweb-application

Updated Jul 13, 2026

criticalEPSS 0.004

CVE-2026-9182 arcgis server vulnerability

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

CVE-2026-9182linuxwindowscloud-securityweb-application

Updated Jul 13, 2026

critical

CVE-2026-13019 Esri Portal for ArcGIS vulnerability

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVE-2026-13019linuxwindowsapi-securitycloud-security

Updated Jul 12, 2026

high

CVE-2026-13020 Esri Portal for ArcGIS vulnerability

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVE-2026-13020linuxwindowsapi-securitycloud-security

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-59998 openssh vulnerability

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

CVE-2026-59998windowsnetwork-security

Updated Jul 12, 2026

highEPSS 0.002

Google Chrome Windows Core Use-After-Free Sandbox Escape Vulnerability

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15120browserwindowsmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Windows Codecs Sandbox Escape Vulnerability

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15122browserwindowsinput-validation

Updated Jul 10, 2026

highEPSS 0.005

CoreWCF Net Framing Premature EOF CPU Denial of Service Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote attacker that can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding endpoint can trigger premature EOF handling in the CoreWCF net.tcp, net.pipe, or net.uds framing handshake and pin one server thread-pool worker at full CPU per connection. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54772dotnetwindowsdenial-of-serviceunix-domain-sockets

Updated Jul 10, 2026

mediumEPSS 0.002

CoreWCF WS-Security Document-Wide Signature Lookup Bypass Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated remote attacker to place a SOAP header before wsse:Security and cause WSSecurityOneDotZeroReceiveSecurityHeader to verify an attacker-supplied signature instead of the security header signature. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54773dotnetwindowscryptographysaml

Updated Jul 10, 2026

highEPSS 0.002

CoreWCF SAML Non-X.509 Signature Verification Bypass Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 signing token, allowing an attacker to reference a non-X.509 SecurityToken key identifier and bypass assertion signature verification. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54774dotnetwindowsauthentication-bypasscryptography

Updated Jul 10, 2026

mediumEPSS 0.003

CoreWCF Kafka Transport Tombstone Record Denial of Service Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-value tombstone record, causing a persistent endpoint denial of service for attackers with produce permission. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54775dotnetwindowsdenial-of-service

Updated Jul 10, 2026

mediumEPSS 0.001

CoreWCF Unix Domain Socket PosixIdentity Security Upgrade Bypass Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted on Unix Domain Sockets with PosixIdentity client credentials can accept connections that skip the application/unixposix stream upgrade before dispatching messages, bypassing framing-layer identity checks in UnixPosixIdentitySecurityUpgradeProvider. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54776dotnetwindowsauthentication-bypassunix-domain-sockets

Updated Jul 10, 2026

mediumEPSS 0.001

CoreWCF Unix Domain Socket POSIX Identity Race Condition Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connections to attribute one connection's identity to another or crash the host process under contention. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54778dotnetwindowsrace-conditionunix-domain-sockets

Updated Jul 10, 2026

mediumEPSS 0.003

CoreWCF SAML Token Replay Cache Bypass Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a captured token to be reused. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54779dotnetwindowsauthentication-bypasssaml

Updated Jul 10, 2026

lowEPSS 0.002

CoreWCF WS-Security Weak Digest Algorithm Acceptance Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:SignedInfo SignatureMethod against the configured SecurityAlgorithmSuite but does not validate each ds:Reference DigestMethod, allowing a sender to use a rejected digest algorithm such as SHA-1 while the message is still accepted. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54780dotnetwindowscryptographysaml

Updated Jul 10, 2026

highEPSS 0.002

CoreWCF SAML SubjectConfirmation Holder-of-Key Bypass Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfirmation method URIs or holder-of-key proof keys in SamlSecurityTokenHandler, allowing holder-of-key downgrade or custom confirmation method assertions to authenticate a subject without proving authority over the assertion. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54781dotnetwindowsauthentication-bypasscryptography

Updated Jul 10, 2026

criticalEPSS 0.002

CoreWCF SAML Token Signature Validation Authentication Bypass Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54782dotnetwindowsauthentication-bypasscryptography

Updated Jul 10, 2026

highEPSS 0.001

CoreWCF WS-Security Signature Target Replay Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers the expected Security header target, allowing an attacker with one captured signed SOAP envelope to replay arbitrary service operations as the victim principal. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54783dotnetwindowsauthentication-bypasscryptography

Updated Jul 10, 2026

highEPSS 0.002

CoreWCF SPNEGO SecurityContextToken Proof Key Exposure Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used, allowing an observer to impersonate the authenticated Windows principal and decrypt or forge WS-SecureConversation traffic. This issue is fixed in version 1.9.1.

CVE-2026-54784dotnetwindowsinformation-disclosuresaml

Updated Jul 10, 2026

highEPSS 0.001

BOSH Windows Stemcell Builder SYSTEM Privilege Escalation Vulnerability

Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.

CVE-2026-47830windowscloud-securityprivilege-escalation

Updated Jul 10, 2026

highEPSS 0.002

BOSH Windows Stemcell Builder Weak Random Password Vulnerability

Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.

CVE-2026-47831windowsnetwork-securitycloud-securitycryptography

Updated Jul 10, 2026

critical

XenCons Windows PV Driver Missing Security Descriptor Vulnerability

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464

CVE-2025-27462windowsvirtualization

Updated Jul 9, 2026

critical

XenIface Windows PV Driver Missing Security Descriptor Vulnerability

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464

CVE-2025-27463windowsvirtualization

Updated Jul 9, 2026

critical

XenBus Windows PV Driver Missing Security Descriptor Vulnerability

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464

CVE-2025-27464windowsvirtualization

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.988

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

CVE-2008-4250windowsmicrosoftremote-code-executionmemory-corruption

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.641

Microsoft Windows Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-32202windowsmicrosoft

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.046

Microsoft Windows Link Following Vulnerability

Microsoft Windows contains a link following vulnerability that allows for privilege escalation

CVE-2025-60710windowsmicrosoftpath-traversalprivilege-escalation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.122

Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation

CVE-2023-36424windowsmicrosoftinformation-disclosure

Updated Jul 9, 2026