| | CVE-2026-42986 | Microsoft | high | 7.8 | — | | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-42978 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-42977 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-42979 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-42991 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-42989 | Microsoft | high | 7.8 | — | | Improper link resolution before file access ('link following') in Winlogon allows an authorized atta… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-44809 | Microsoft | high | 7.8 | — | | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate pri… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-44810 | Microsoft | high | 8.4 | — | | Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-44811 | Microsoft | high | 7.8 | — | | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-44808 | Microsoft | high | 7.8 | — | | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-44807 | Microsoft | high | 7.8 | — | | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-44815 | Microsoft | critical | 9.8 | — | | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code o… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-42983 | Microsoft | high | 7.8 | — | | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-44802 | Microsoft | high | 7.8 | — | | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-42987 | Microsoft | high | 8.1 | — | | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-42993 | Microsoft | high | 7.5 | — | | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code … | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-44813 | Microsoft | high | 7.8 | — | | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-44804 | Microsoft | high | 7.8 | — | | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-26142 | Microsoft | critical | 9.8 | 1.9%
| | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute c… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-32193 | Microsoft | high | 8.8 | 0.3%
| | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Ku… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-33113 | Microsoft | medium | 5.4 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-40371 | Microsoft | high | 8.8 | 0.6%
| | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-40376 | Microsoft | high | 7.5 | 0.7%
| | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privilege… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41098 | Microsoft | high | 8.4 | 0.8%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-42835 | Microsoft | high | 8.1 | 1.3%
| | Improper neutralization of special elements in output used by a downstream component ('injection') i… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-42902 | Microsoft | high | 7.8 | 0.3%
| | Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges lo… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-42908 | Microsoft | high | 7.5 | 0.9%
| | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-42909 | Microsoft | high | 7.5 | 0.4%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Remot… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-42913 | Microsoft | high | 7.5 | 0.5%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Remot… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-42985 | Microsoft | high | 8.8 | 1.0%
| | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-42992 | Microsoft | high | 7.5 | 0.5%
| | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44799 | Microsoft | high | 7.5 | 0.5%
| | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44801 | Microsoft | high | 7.5 | 0.5%
| | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44803 | Microsoft | high | 7.8 | 0.4%
| | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44812 | Microsoft | high | 7.8 | 0.4%
| | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44817 | Microsoft | high | 7.8 | 0.4%
| | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44818 | Microsoft | high | 7.0 | 0.3%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Micro… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44819 | Microsoft | high | 7.8 | 0.5%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44820 | Microsoft | high | 7.8 | 0.4%
| | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44821 | Microsoft | medium | 5.5 | 0.5%
| | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44822 | Microsoft | high | 8.2 | 0.5%
| | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44823 | Microsoft | high | 7.8 | 0.4%
| | Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code l… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44824 | Microsoft | high | 7.8 | 0.5%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45453 | Microsoft | medium | 5.4 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45454 | Microsoft | medium | 6.5 | 1.6%
| | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office S… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45455 | Microsoft | low | 3.3 | 0.6%
| | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45456 | Microsoft | high | 8.4 | 0.4%
| | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45457 | Microsoft | high | 7.8 | 0.4%
| | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45458 | Microsoft | high | 8.4 | 0.4%
| | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45459 | Microsoft | low | 3.3 | 0.4%
| | Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a s… | Jun 9, 2026 | Jul 23, 2026 |