CVE-2026-48568 Secure Boot Security Feature Bypass Vulnerability
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-48568 US
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-48568 US
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-48563 US
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-47654 US
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-47652 US
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-47653 US
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-8863 US
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-47648 US
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-45588 US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47641 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47639 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47638 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47637 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-47635 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-41098 US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-47631 Microsoft US
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-32193 Microsoft US
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-41092 Microsoft US
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-47292 US
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-47289 US
Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.
EPSS 0.00 CVE-2026-47288 US
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
EPSS 0.01 CVE-2026-47287 US
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
EPSS 0.15 CVE-2026-45657 US
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-45656 US
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
EPSS 0.00 CVE-2026-45655 US
User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45650 Microsoft US
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-45648 veřejná správa US
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
EPSS 0.00 CVE-2026-45642 Microsoft US
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-45634 US
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-45641 US
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-45607 US
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
EPSS 0.00 CVE-2026-45606 Microsoft US
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45640 US
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-45639 US
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45605 US
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-45583 Microsoft US
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-45503 Microsoft US
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
EPSS 0.20 CVE-2026-45502 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-45501 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-45500 Microsoft US
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
EPSS 0.00 CVE-2026-45491 US
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45490 US
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45487 US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45453 Microsoft US
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-42902 Microsoft US
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-34335 US
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-33828 US
Information published.
EPSS 0.00 CVE-2026-40404 US
Information published.
EPSS 0.00 CVE-2026-40409 US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45483 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45479 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45468 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45467 Microsoft US
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-41108 Microsoft US
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-47298 Microsoft US
Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-45482 Microsoft GitHub US
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-40376 US
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-48569 US
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
EPSS 0.00 CVE-2026-45602 US
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-40371 Microsoft US
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-42828 US