| | CVE-2026-33834 | Microsoft | high | 7.8 | — | | Improper access control in Windows Event Logging Service allows an authorized attacker to elevate pr… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-33839 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-33840 | Microsoft | high | 7.8 | — | | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-33841 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34329 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34330 | Microsoft | high | 7.8 | — | | Integer overflow or wraparound in Windows Win32K - GRFX allows an authorized attacker to elevate pri… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34331 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34333 | Microsoft | high | 7.8 | — | | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34342 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34343 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized at… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34344 | Microsoft | high | 7.8 | — | | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34345 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34347 | Microsoft | high | 7.0 | — | | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34350 | Microsoft | medium | 6.5 | — | | Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34351 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35415 | Microsoft | high | 7.8 | — | | Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35416 | Microsoft | high | 7.0 | — | | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35417 | Microsoft | high | 7.8 | — | | Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an au… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35418 | Microsoft | high | 7.8 | — | | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate pr… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35419 | Microsoft | medium | 5.5 | — | | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35420 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35421 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35422 | Microsoft | medium | 6.5 | — | | Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized atta… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35424 | Microsoft | high | 7.5 | — | | Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol a… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35433 | Microsoft | high | 7.3 | — | | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35438 | Microsoft | high | 8.3 | — | | Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges ov… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35440 | Microsoft | medium | 5.5 | — | | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized … | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40360 | Microsoft | high | 7.8 | 0.1%
| | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40363 | Microsoft | high | 8.4 | — | | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40364 | Microsoft | high | 8.4 | — | | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40366 | Microsoft | high | 8.4 | — | | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40377 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevat… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40380 | Microsoft | medium | 6.2 | — | | Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execu… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40399 | Microsoft | high | 7.8 | — | | Stack-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges lo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40407 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40408 | Microsoft | high | 7.8 | — | | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges lo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40410 | Microsoft | high | 7.0 | — | | Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40415 | Microsoft | high | 8.1 | — | | Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40417 | Microsoft | high | 7.8 | — | | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40419 | Microsoft | high | 7.8 | — | | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41088 | Microsoft | high | 7.8 | — | | External control of file name or path in Windows Ancillary Function Driver for WinSock allows an aut… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41089 | Microsoft | critical | 9.8 | — | | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41094 | Microsoft | high | 8.8 | — | | Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an una… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41095 | Microsoft | high | 7.8 | — | | Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41096 | Microsoft | critical | 9.8 | — | | Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code … | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41101 | Microsoft | high | 7.1 | — | | Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing l… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41102 | Microsoft | high | 7.1 | — | | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41109 | Microsoft | high | 8.8 | — | | Improper neutralization of special elements in output used by a downstream component ('injection') i… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41611 | Microsoft | high | 7.8 | — | | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code … | May 12, 2026 | May 13, 2026 |
| | CVE-2026-41612 | Microsoft | medium | 5.5 | — | | Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose informatio… | May 12, 2026 | May 13, 2026 |