|
851
|
7.1 |
HIGH
Network
|
-
|
-
|
Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.
|
CWE-357
Insufficient UI Warning of Dangerous Operations
|
CVE-2026-26151
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
852
|
7.0 |
HIGH
Local
|
-
|
-
|
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2026-26152
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
853
|
7.8 |
HIGH
Local
|
-
|
-
|
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-26153
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
854
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
|
CWE-20
Improper Input Validation
|
CVE-2026-26154
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
855
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
|
CWE-126
Buffer Over-read
|
CVE-2026-26155
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
856
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.
|
CWE-20 CWE-122 CWE-125
Improper Input Validation Heap-based Buffer Overflow Out-of-bounds Read
|
CVE-2026-26156
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
857
|
7.8 |
HIGH
Local
|
-
|
-
|
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-26159
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
858
|
7.8 |
HIGH
Local
|
-
|
-
|
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-26160
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
859
|
7.8 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
|
CWE-20 CWE-822
Improper Input Validation Untrusted Pointer Dereference
|
CVE-2026-26161
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
860
|
7.8 |
HIGH
Local
|
-
|
-
|
Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.
|
CWE-843
Type Confusion
|
CVE-2026-26162
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|