CVE-2026-42909 Remote Desktop Client Remote Code Execution Vulnerability
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-42909 US
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-42909 US
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-42908 US
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
EPSS 0.01 CVE-2026-42907 US
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-42906 US
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
EPSS 0.02 CVSS 7.8 CVE-2026-42905 US
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
EPSS 0.00 CVE-2026-42904 US
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-42837 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-42836 US
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50512 Microsoft US
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50511 Microsoft US
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
EPSS 0.05 CVE-2026-50507 US
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
EPSS 0.54 CVE-2026-49160 US
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-48574 US
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-48565 US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-48562 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-48560 Microsoft US
Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-47656 US
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.35 CVE-2026-45484 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45481 Microsoft US
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-47643 US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47640 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47634 Microsoft US
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-47293 Microsoft US
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-47284 US
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-47281 US
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
EPSS 0.00 CVE-2026-45658 US
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45647 Microsoft US
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-45654 US
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45653 US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-45644 Microsoft US
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-45608 US
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45603 US
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-45635 US
Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45600 US
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45596 US
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-45636 US
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45598 US
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45601 US
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-45599 US
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.00 CVE-2026-45595 US
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-45604 US
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-45594 US
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
EPSS 0.02 CVE-2026-45591 US
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
EPSS 0.04 CVE-2026-45586 US
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45476 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45465 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45464 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45462 Microsoft US
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.02 CVE-2026-45454 Microsoft veřejná správa finance zdravotnictví školství US
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-42835 Microsoft US
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-42829 US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-33113 Microsoft US
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
EPSS 0.02 CVE-2026-26142 Nuance zdravotnictví US
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-49161 Microsoft US
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-48583 US
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-48578 US
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
EPSS 0.01 CVE-2026-48576 US
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-48575 US
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
EPSS 0.01 CVE-2026-48573 US
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-48570 US