| | CVE-2026-49803 | Microsoft | high | 7.0 | 0.2%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-49805 | Microsoft | high | 7.0 | — | | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49806 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49802 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50333 | Microsoft | high | 7.8 | 0.2%
| | Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker … | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50311 | Microsoft | high | 7.8 | 0.2%
| | Improper access control in Windows Server allows an authorized attacker to elevate privileges locall… | Jul 14, 2026 | Jul 17, 2026 |
| | CVE-2026-50308 | Microsoft | high | 7.8 | — | | Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute co… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49800 | Microsoft | high | 7.8 | 0.2%
| | Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authori… | Jul 14, 2026 | Jul 17, 2026 |
| | CVE-2026-49798 | Microsoft | critical | 9.3 | — | | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49797 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49795 | Microsoft | high | 8.8 | — | | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49796 | Microsoft | high | 7.8 | 0.4%
| | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-49793 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49792 | Microsoft | high | 7.8 | — | | Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to ex… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49791 | Microsoft | high | 7.1 | — | | Improper link resolution before file access ('link following') in Windows Routing and Remote Access … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49790 | Microsoft | high | 7.3 | — | | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49789 | Microsoft | high | 7.3 | — | | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges loca… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49783 | Microsoft | high | 7.8 | 0.3%
| | Improperly implemented security check for standard in Windows Secure Boot allows an authorized attac… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-49183 | Microsoft | high | 7.0 | 0.2%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-49181 | Microsoft | high | 7.5 | 0.8%
| | Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to ele… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-49178 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to exec… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-48581 | Microsoft | high | 7.8 | 0.2%
| | Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to ele… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-48564 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-44800 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-40400 | Microsoft | high | 8.0 | — | | Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a n… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-58610 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-58609 | Microsoft | high | 7.8 | 0.3%
| | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code l… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-58608 | Microsoft | high | 8.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-58602 | Microsoft | high | 7.8 | — | | Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges loc… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-58526 | Microsoft | high | 7.0 | — | | Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54127 | Microsoft | high | 7.4 | 0.2%
| | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50694 | Microsoft | high | 8.1 | — | | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-56155 | Microsoft | high | 7.8 | — | ⚠ KEV | Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-55144 | Microsoft | high | 7.1 | 0.2%
| | Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering l… | Jul 14, 2026 | Jul 21, 2026 |
| | CVE-2026-54122 | Microsoft | high | 8.4 | 0.3%
| | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-54995 | Microsoft | high | 8.1 | — | | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54999 | Microsoft | high | 8.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54996 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54114 | Microsoft | high | 7.8 | — | | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54982 | Microsoft | high | 8.8 | — | | Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an una… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54109 | Microsoft | high | 7.8 | — | | Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54992 | Microsoft | high | 8.4 | — | | Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-55004 | Microsoft | high | 7.8 | — | | Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54112 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-55001 | Microsoft | high | 7.8 | — | | Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54993 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54986 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges loc… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54107 | Microsoft | high | 8.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54991 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54111 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 15, 2026 |