CVE-2026-55000 Windows USB Print Driver Elevation of Privilege Vulnerability
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-55000 US
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-55000 US
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-54990 US
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-54987 US
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-54989 US
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50695 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-54983 veřejná správa US
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-50663 US
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-45496 US
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-47282 GitHub US
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50506 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-49784 Microsoft US
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-49177 US
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
EPSS 0.00 CVE-2026-49174 Microsoft US
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-49173 US
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-49172 US
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-49175 US
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-49176 US
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-49171 Microsoft US
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-49170 US
Use after free in DNS Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-49169 US
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-49168 US
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-49167 US
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-49166 Microsoft US
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-49165 Microsoft US
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-49164 veřejná správa US
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-48571 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-48572 US
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-42990 US
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-47300 US
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
EPSS 0.01 CVE-2026-42975 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-42900 Microsoft US
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-34346 US
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-34349 US
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-47296 Microsoft US
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-42982 US
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-56182 US
Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50375 US
The Patch for this issue was released but the CVE was inadvertently left out of the Patch Tuesday June 2026 release
KEV ✓ EPSS 0.16 CVE-2026-58644 Microsoft US
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50650 US
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
EPSS 0.01 CVE-2026-50649 US
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50648 US
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50647 veřejná správa US
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
EPSS 0.01 CVE-2026-50646 US
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50527 US
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50525 US
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50411 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50355 veřejná správa US
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50324 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50368 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50304 veřejná správa US
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.00 CVE-2026-47304 US
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50653 veřejná správa US
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
EPSS 0.02 CVE-2026-50652 veřejná správa US
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-47302 US
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50462 US
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-58640 US
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50458 Microsoft US
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50441 US
Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50466 Microsoft US
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50377 US