CVE-2026-68880 Windows Win32k Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-68880 US
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-68880 US
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-68842 US
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-68848 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-68840 US
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-68839 US
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-68838 US
Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-68843 Microsoft US
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-68834 US
Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-68827 US
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-68831 US
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-68828 US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-68780 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-68779 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-68778 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-68777 Microsoft US
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-68776 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-68775 Microsoft US
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67648 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-67642 Microsoft US
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-67641 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67639 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67638 Microsoft US
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67393 Microsoft US
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67390 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-67388 Microsoft US
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67386 Microsoft US
Use after free in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-67385 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-67381 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67380 Microsoft US
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-66820 US
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-66818 Microsoft US
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
EPSS 0.01 CVE-2026-66816 Microsoft US
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-66814 Microsoft US
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-56172 US
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVSS 7.8 CVE-2026-62697 US
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-62813 US
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
EPSS 0.01 CVSS 6.5 CVE-2026-62762 US
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
EPSS 0.00 CVE-2026-62759 US
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-62810 US
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58611 US
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-56198 Microsoft US
Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-56177 US
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
KEV ✓ EPSS 0.01 CVE-2026-85880 Microsoft US
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-85877 US
Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-84001 US
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83999 US
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-83998 US
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83996 US
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
EPSS 0.00 CVE-2026-83991 US
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-70290 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83976 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83975 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83974 US
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83979 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83988 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83969 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83986 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83955 US
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69492 US
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-72937 US