| | CVE-2026-50686 | Microsoft | high | 8.1 | 0.7%
| | Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized … | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50687 | Microsoft | high | 8.8 | — | | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50683 | Microsoft | high | 8.0 | — | | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privilege… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50685 | Microsoft | high | 7.5 | — | | Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54121 | Microsoft | high | 8.8 | — | | Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacke… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50680 | Microsoft | high | 8.2 | 0.4%
| | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges lo… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50688 | Microsoft | high | 7.8 | — | | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50679 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to el… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54115 | Microsoft | high | 7.8 | — | | Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50677 | Microsoft | high | 7.8 | — | | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50676 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50674 | Microsoft | high | 7.0 | — | | Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges local… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50673 | Microsoft | high | 7.8 | — | | Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges local… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50672 | Microsoft | high | 7.0 | — | | Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50670 | Microsoft | high | 8.8 | — | | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50669 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50667 | Microsoft | high | 7.8 | 2.2%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50666 | Microsoft | high | 8.8 | 0.6%
| | Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate … | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50655 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50518 | Microsoft | critical | 9.8 | — | | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50509 | Microsoft | high | 7.8 | — | | Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50503 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50501 | Microsoft | high | 7.8 | — | | Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50491 | Microsoft | high | 7.0 | 0.3%
| | Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privilege… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50505 | Microsoft | high | 7.5 | — | | Use after free in Windows Message Queuing allows an authorized attacker to execute code over a netwo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50498 | Microsoft | high | 7.8 | — | | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50490 | Microsoft | high | 7.0 | — | | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50494 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50489 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges loc… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50499 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elev… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50500 | Microsoft | high | 7.5 | — | | Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a networ… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50488 | Microsoft | high | 7.8 | — | | Improper neutralization of special elements used in a command ('command injection') in Windows Clipb… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50487 | Microsoft | high | 8.1 | 0.7%
| | Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50486 | Microsoft | high | 7.8 | — | | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50502 | Microsoft | high | 8.0 | 0.6%
| | Insufficient granularity of access control in Windows Event Logging Service allows an authorized att… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50484 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50482 | Microsoft | high | 7.3 | — | | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50480 | Microsoft | high | 7.8 | 0.2%
| | Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized … | Jul 14, 2026 | Jul 17, 2026 |
| | CVE-2026-50479 | Microsoft | high | 7.8 | 0.3%
| | Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate pri… | Jul 14, 2026 | Jul 17, 2026 |
| | CVE-2026-50477 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50459 | Microsoft | high | 7.0 | — | | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50406 | Microsoft | high | 7.0 | 0.3%
| | Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50450 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50476 | Microsoft | high | 7.8 | — | | Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50458 | Microsoft | high | 7.8 | — | | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privilege… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50444 | Microsoft | high | 8.8 | — | | Missing authentication for critical function in Windows Server Update Service allows an authorized a… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50474 | Microsoft | high | 8.8 | — | | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50362 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker t… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50447 | Microsoft | critical | 9.8 | — | | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50417 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | Jul 14, 2026 | Jul 15, 2026 |