CVE-2026-65780 Windows Autopilot Elevation of Privilege Vulnerability
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65780 veřejná správa US
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65780 veřejná správa US
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
EPSS 0.01 CVE-2026-62814 veřejná správa US
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-62761 veřejná správa US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-61920 veřejná správa US
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
EPSS 0.03 CVSS 7.5 CVE-2026-62893 Microsoft veřejná správa US 2 zdrojů
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-62820 veřejná správa US
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
EPSS 0.01 CVE-2026-62817 veřejná správa telekomunikace US
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-62795 veřejná správa US
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
EPSS 0.00 CVE-2026-62716 veřejná správa US
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-50481 veřejná správa US
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-50516 Microsoft veřejná správa telekomunikace finance výroba a průmysl US
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50682 veřejná správa US
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-50684 veřejná správa US
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50424 veřejná správa US
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-50444 veřejná správa US
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
EPSS 0.01 CVSS 6.5 CVE-2026-50366 veřejná správa US
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
EPSS 0.01 CVE-2026-50370 veřejná správa zdravotnictví finance energetika US
Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
EPSS 0.01 CVE-2026-50328 veřejná správa US
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-49178 veřejná správa US
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-40378 veřejná správa US
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
EPSS 0.01 CVSS 6.5 CVE-2026-57976 veřejná správa US
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-54119 veřejná správa US
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-55001 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50695 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-54983 veřejná správa US
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-49164 veřejná správa US
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50647 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50411 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50355 veřejná správa US
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50324 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50368 veřejná správa US
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50304 veřejná správa US
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50653 veřejná správa US
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
EPSS 0.02 CVE-2026-50652 veřejná správa US
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-56197 veřejná správa US
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-42987 veřejná správa US
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.02 CVE-2026-45454 Microsoft veřejná správa finance zdravotnictví školství US
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-45648 veřejná správa US
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
EPSS 0.07 CVE-2026-42980 veřejná správa US