| | CVE-2026-50461 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50399 | Microsoft | high | 7.8 | — | | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50457 | Microsoft | high | 7.8 | — | | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50462 | Microsoft | high | 7.8 | — | | External control of file name or path in Windows Ancillary Function Driver for WinSock allows an aut… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50439 | Microsoft | high | 8.1 | — | | Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50441 | Microsoft | high | 7.8 | — | | Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50435 | Microsoft | high | 7.8 | 0.2%
| | Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges local… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50402 | Microsoft | high | 7.8 | — | | Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50466 | Microsoft | high | 7.8 | — | | Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50451 | Microsoft | high | 7.1 | — | | Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) all… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50367 | Microsoft | high | 7.8 | — | | Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an auth… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50421 | Microsoft | high | 7.8 | 0.3%
| | Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences … | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50422 | Microsoft | high | 7.8 | — | | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50427 | Microsoft | high | 7.8 | 0.2%
| | Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges local… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50413 | Microsoft | high | 8.8 | — | | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50385 | Microsoft | high | 8.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50426 | Microsoft | medium | 6.8 | 0.4%
| | Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50365 | Microsoft | high | 8.0 | 0.5%
| | Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges ove… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50454 | Microsoft | high | 7.8 | 0.4%
| | Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate priv… | Jul 14, 2026 | Jul 17, 2026 |
| | CVE-2026-50469 | Microsoft | high | 7.8 | — | | Improper link resolution before file access ('link following') in Windows Projected File System allo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50369 | Microsoft | high | 8.8 | — | | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privilege… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50436 | Microsoft | high | 7.8 | — | | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50382 | Microsoft | high | 8.8 | — | | Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code local… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50344 | Microsoft | high | 7.8 | 0.3%
| | Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50448 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50405 | Microsoft | high | 7.8 | 0.2%
| | Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized … | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50397 | Microsoft | high | 7.0 | — | | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50346 | Microsoft | high | 7.8 | 0.3%
| | Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50378 | Microsoft | high | 7.8 | 0.2%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 21, 2026 |
| | CVE-2026-50423 | Microsoft | high | 7.8 | — | | Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locall… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50391 | Microsoft | high | 7.8 | 0.3%
| | Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privi… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50433 | Microsoft | high | 7.8 | — | | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50403 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50379 | Microsoft | high | 7.5 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50414 | Microsoft | high | 7.5 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50398 | Microsoft | high | 8.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50336 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges loca… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50371 | Microsoft | high | 7.0 | 0.2%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50449 | Microsoft | high | 7.0 | — | | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50410 | Microsoft | high | 7.0 | — | | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50388 | Microsoft | high | 7.8 | — | | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50353 | Microsoft | high | 7.8 | — | | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50373 | Microsoft | high | 7.8 | — | | Improper access control in Microsoft Windows Search Component allows an authorized attacker to eleva… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50358 | Microsoft | high | 7.0 | — | | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50404 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50340 | Microsoft | high | 8.5 | — | | Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50317 | Microsoft | high | 7.8 | 0.2%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50361 | Microsoft | high | 7.8 | — | | Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges l… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50375 | Microsoft | medium | 6.3 | — | | Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges lo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50335 | Microsoft | high | 7.8 | 0.3%
| | Improper access control in Windows Operating Systems allows an authorized attacker to elevate privil… | Jul 14, 2026 | Jul 23, 2026 |