| | CVE-2026-24290 | Microsoft | high | 7.8 | 0.0%
| | Improper access control in Windows Projected File System allows an authorized attacker to elevate pr… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-24291 | Microsoft | high | 7.8 | 0.1%
| | Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBro… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-24292 | Microsoft | high | 7.8 | 0.0%
| | Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to eleva… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-24293 | Microsoft | high | 7.8 | 0.0%
| | Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attac… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-24294 | Microsoft | high | 7.8 | 0.1%
| | Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-24295 | Microsoft | high | 7.0 | 0.0%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-24296 | Microsoft | high | 7.0 | 0.0%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-24297 | Microsoft | medium | 6.5 | 0.0%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25165 | Microsoft | high | 7.8 | 0.0%
| | Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate pr… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25166 | Microsoft | high | 7.8 | 0.5%
| | Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to e… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25167 | Microsoft | high | 7.4 | 0.0%
| | Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privile… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25168 | Microsoft | medium | 6.2 | 0.0%
| | Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny ser… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25169 | Microsoft | medium | 6.2 | 0.0%
| | Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service local… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25170 | Microsoft | high | 7.0 | 0.0%
| | Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25171 | Microsoft | high | 7.0 | 0.0%
| | Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25172 | Microsoft | high | 8.0 | 0.1%
| | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authori… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25173 | Microsoft | high | 8.0 | 0.1%
| | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authori… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25174 | Microsoft | high | 7.8 | 0.0%
| | Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate pr… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25175 | Microsoft | high | 7.8 | 0.0%
| | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25176 | Microsoft | high | 7.8 | 0.0%
| | Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25177 | Microsoft | high | 8.8 | 0.1%
| | Improper restriction of names for files and other resources in Active Directory Domain Services allo… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25178 | Microsoft | high | 7.0 | 0.0%
| | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25179 | Microsoft | high | 7.0 | 0.0%
| | Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allo… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25180 | Microsoft | medium | 5.5 | 0.0%
| | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose infor… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25181 | Microsoft | high | 7.5 | 0.1%
| | Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a ne… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25185 | Microsoft | medium | 5.3 | 0.1%
| | Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows a… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25186 | Microsoft | medium | 5.5 | 0.1%
| | Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25187 | Microsoft | high | 7.8 | 0.1%
| | Improper link resolution before file access ('link following') in Winlogon allows an authorized atta… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25188 | Microsoft | high | 8.8 | 0.1%
| | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate p… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25189 | Microsoft | high | 7.8 | 0.0%
| | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-25190 | Microsoft | high | 7.8 | 0.1%
| | Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26105 | Microsoft | high | 8.1 | 0.0%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26111 | Microsoft | high | 8.0 | 0.1%
| | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authori… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26112 | Microsoft | high | 7.8 | 0.1%
| | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute c… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26113 | Microsoft | high | 8.4 | 0.0%
| | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26114 | Microsoft | high | 8.8 | 0.6%
| | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-23656 | Microsoft | medium | 5.9 | 0.0%
| | Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attac… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-20967 | Microsoft | high | 8.8 | 0.1%
| | Improper input validation in System Center Operations Manager allows an authorized attacker to eleva… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26121 | Microsoft | high | 7.5 | 0.1%
| | Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform … | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26115 | Microsoft | high | 8.8 | 0.1%
| | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevat… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26116 | Microsoft | high | 8.8 | 0.1%
| | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26128 | Microsoft | high | 7.8 | 0.0%
| | Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26132 | Microsoft | high | 7.8 | 0.1%
| | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26134 | Microsoft | high | 7.8 | 0.1%
| | Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileg… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-23674 | Microsoft | high | 7.5 | 0.1%
| | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to b… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-26148 | Microsoft | high | 8.1 | 0.1%
| | External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-23654 | Microsoft | high | 8.8 | 0.1%
| | Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unau… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-23661 | Microsoft | high | 7.5 | 0.0%
| | Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacke… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-23662 | Microsoft | high | 7.5 | 0.0%
| | Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker t… | Mar 10, 2026 | Mar 13, 2026 |
| | CVE-2026-23665 | Microsoft | high | 7.8 | 0.0%
| | Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate … | Mar 10, 2026 | Mar 13, 2026 |