<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Microsoft Windows (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/windows.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/windows-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Microsoft Windows (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:26 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-50033 – Local privilege escalation due to DLL hijacking vulnerability. The following pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-50033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-50033</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-50033</strong></p>
  <p>Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44682 – Local privilege escalation due to DLL hijacking vulnerability. The following pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44682</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44682</strong></p>
  <p>Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44609 – Local privilege escalation due to EXE hijacking vulnerability. The following pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44609</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44609</strong></p>
  <p>Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42061 – Local privilege escalation due to excessive permissions assigned to child proces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42061</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42061</strong></p>
  <p>Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8036 – Improper input validation in NI-PAL may allow a local authenticated user to acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8036</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8036</strong></p>
  <p>Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8035 – Improper input validation in the NI-PAL kernel driver may allow a local authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8035</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8035</strong></p>
  <p>Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52011 – launch-editor allows users to open files with line numbers in editor from Node.j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52011</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52011</strong></p>
  <p>launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8501 – Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8501</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8501</strong></p>
  <p>Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-782</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4991 – Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4991</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4991</strong></p>
  <p>Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32325 – Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32325</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32325</strong></p>
  <p>Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-268</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27788 – Incorrect permission assignment for critical resource issue exists in ServerView...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27788</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27788</strong></p>
  <p>Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10056 – CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10056</guid>
    <pubDate>Fri, 29 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10056</strong></p>
  <p>CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious cross-origin web page visited by the victim. The High security mode is not affect…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9994 – Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9994</guid>
    <pubDate>Thu, 28 May 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9994</strong></p>
  <p>Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9984 – Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9984</guid>
    <pubDate>Thu, 28 May 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9984</strong></p>
  <p>Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9966 – Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9966</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9966</strong></p>
  <p>Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9949 – Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9949</guid>
    <pubDate>Thu, 28 May 2026 23:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9949</strong></p>
  <p>Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9945 – Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9945</guid>
    <pubDate>Thu, 28 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9945</strong></p>
  <p>Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9937 – Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9937</guid>
    <pubDate>Thu, 28 May 2026 23:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9937</strong></p>
  <p>Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9932 – Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9932</guid>
    <pubDate>Thu, 28 May 2026 23:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9932</strong></p>
  <p>Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9928 – Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9928</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9928</strong></p>
  <p>Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9924 – Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.21...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9924</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9924</strong></p>
  <p>Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9905 – Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9905</guid>
    <pubDate>Thu, 28 May 2026 23:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9905</strong></p>
  <p>Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9890 – Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9890</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9890</strong></p>
  <p>Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10000 – Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10000</guid>
    <pubDate>Thu, 28 May 2026 23:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10000</strong></p>
  <p>Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10044 – Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10044</guid>
    <pubDate>Thu, 28 May 2026 22:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10044</strong></p>
  <p>Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequences. Attackers can bypass the incomplete path traversal guard, which only blocks forward slashes and…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32996 – This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32996</guid>
    <pubDate>Thu, 28 May 2026 05:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32996</strong></p>
  <p>This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42184 – Tauri is a framework for building binaries for all major desktop platforms. From...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42184</guid>
    <pubDate>Wed, 27 May 2026 15:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42184</strong></p>
  <p>Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to http://<scheme>.localhost/ because those platforms' WebView implementations cannot serve custom URI scheme…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24193 – NVIDIA Display Driver for Windows and Linux contains a vulnerability where an at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24193</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24193</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24191 – NVIDIA Display Driver for Windows contains a vulnerability where an attacker cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24191</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24191</strong></p>
  <p>NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24190 – NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24190</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24190</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45721 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45721</guid>
    <pubDate>Tue, 26 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45721</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured server root — looking for a file named handler.lua to execute as the request handler. The loop terminates only after 100 ancestor steps or when filepath.Dir returns…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9489 – NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9489</guid>
    <pubDate>Mon, 25 May 2026 02:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9489</strong></p>
  <p>NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging t…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48831 – Wine ships a .desktop file that registers itself as a MIME handler for EXE files...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48831</guid>
    <pubDate>Sun, 24 May 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48831</strong></p>
  <p>Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions of the invoker. This allows escaping Flatpak and Snap sandboxes, because MIME handlers are not intended for use by code interpreters and loaders. NOTE: some par…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8671 – Insertion of sensitive information into log file vulnerability in syslink softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8671</guid>
    <pubDate>Fri, 22 May 2026 14:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8671</strong></p>
  <p>Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure.  This issue affects Avantra: before 25.3.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8670 – Insufficient session expiration vulnerability in syslink software AG Avantra on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8670</guid>
    <pubDate>Fri, 22 May 2026 14:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8670</strong></p>
  <p>Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay).  This issue affects Avantra: before 25.3.1.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9118 – Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9118</guid>
    <pubDate>Wed, 20 May 2026 20:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9118</strong></p>
  <p>Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9112 – Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9112</guid>
    <pubDate>Wed, 20 May 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9112</strong></p>
  <p>Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42834 – Improper access control in Windows Admin Center allows an authorized attacker to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42834</guid>
    <pubDate>Wed, 20 May 2026 13:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42834</strong></p>
  <p>Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47092 – Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47092</guid>
    <pubDate>Mon, 18 May 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47092</strong></p>
  <p>Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud performs its version check, causing execFile() to execute the attacker-supplied executable with cmd.exe arguments, resulti…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37247 – Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteServi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37247</guid>
    <pubDate>Sat, 16 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37247</strong></p>
  <p>Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8398 – A supply chain attack compromised the official installation packages of DAEMON T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8398</guid>
    <pubDate>Fri, 15 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8398</strong></p>
  <p>A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.e…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-506</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7373 – Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7373</guid>
    <pubDate>Fri, 15 May 2026 03:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7373</strong></p>
  <p>Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which would in turn load an OpenSSL configuration file from a static location. This static location would be writable by a pre-existing "vagrant" user, if they already…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45369 – python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45369</guid>
    <pubDate>Thu, 14 May 2026 21:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45369</strong></p>
  <p>python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_protocol.py inserts user-controlled tool_args values directly into shell command strings without any sanitization or escaping. These commands are then executed via /bin/bash -c (Unix) or powershell.exe -Command (Windows), allowing an attacker to inject arbitrary shell commands.…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8574 – Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8574</guid>
    <pubDate>Thu, 14 May 2026 20:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8574</strong></p>
  <p>Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8573 – Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8573</guid>
    <pubDate>Thu, 14 May 2026 20:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8573</strong></p>
  <p>Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8555 – Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8555</guid>
    <pubDate>Thu, 14 May 2026 20:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8555</strong></p>
  <p>Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8547 – Insufficient policy enforcement in Passwords in Google Chrome on Windows prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8547</guid>
    <pubDate>Thu, 14 May 2026 20:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8547</strong></p>
  <p>Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8542 – Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8542</guid>
    <pubDate>Thu, 14 May 2026 20:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8542</strong></p>
  <p>Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8531 – Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.16...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8531</guid>
    <pubDate>Thu, 14 May 2026 20:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8531</strong></p>
  <p>Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8530 – Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8530</guid>
    <pubDate>Thu, 14 May 2026 20:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8530</strong></p>
  <p>Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8519 – Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8519</guid>
    <pubDate>Thu, 14 May 2026 20:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8519</strong></p>
  <p>Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8510 – Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8510</guid>
    <pubDate>Thu, 14 May 2026 20:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8510</strong></p>
  <p>Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26191 – Fleet is open source device management software. Prior to version 4.81.0, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26191</guid>
    <pubDate>Thu, 14 May 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26191</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall is triggered. When a software package (.pkg, .deb, .rpm, .exe, or .msi) is uploaded to Fleet, metadata is extracted from…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24899 – Fleet is open source device management software. Prior to version 4.82.0, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24899</guid>
    <pubDate>Thu, 14 May 2026 20:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24899</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. Because Fleet validates JWT signatures using Microsoft's multi-tenant JWKS endpoint but does not enforce the `aud` (audience) or `iss` (issuer) claims, any Microsoft-signed Azure AD access token conta…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44586 – SiYuan is an open-source personal knowledge management system. From 2.1.12 to be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44586</guid>
    <pubDate>Thu, 14 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44586</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron windows are created with nodeIntegration: true and contextIsolation: false, a successful payload can call Node.…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23998 – Fleet is open source device management software. Prior to version 4.81.0, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23998</guid>
    <pubDate>Thu, 14 May 2026 19:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23998</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstances, this could allow an attacker to impersonate an enrolled Windows device and retrieve sensitive configuration data. Fleet’s Windows MDM management endpoint rel…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30906 – Untrusted search path in the installer for Zoom Rooms for Windows before version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30906</guid>
    <pubDate>Wed, 13 May 2026 19:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30906</strong></p>
  <p>Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30905 – External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30905</guid>
    <pubDate>Wed, 13 May 2026 19:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30905</strong></p>
  <p>External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44470 – The Claude Desktop app gives you Claude Code with a graphical interface built fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44470</guid>
    <pubDate>Wed, 13 May 2026 16:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44470</strong></p>
  <p>The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Windows ran as SYSTEM and did not validate whether the VM bundle directory was a real directory or an NTFS directory junction before creating files within it. A local non-elevated user could replace the use…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47091 – Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk &lt;2.4.0p2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47091</guid>
    <pubDate>Wed, 13 May 2026 10:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47091</strong></p>
  <p>Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whose name matches 'MySQL' or 'MariaDB' (or with write access to a binary referenced by such a service) to execute arbitrary code in the context of the Checkmk agent service, which typically runs as SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44612 – Bytello Share (Windows Edition) installer executable provided by Bytello insecur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44612</guid>
    <pubDate>Wed, 13 May 2026 06:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44612</strong></p>
  <p>Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44307 – Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44307</guid>
    <pubDate>Tue, 12 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44307</strong></p>
  <p>Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42896 – Integer overflow or wraparound in Windows DWM Core Library allows an authorized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42896</guid>
    <pubDate>Tue, 12 May 2026 18:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42896</strong></p>
  <p>Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42825 – Use after free in Windows Telephony Service allows an authorized attacker to ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42825</guid>
    <pubDate>Tue, 12 May 2026 18:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42825</strong></p>
  <p>Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42141 – Xibo is an open source digital signage platform with a web content management sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42141</guid>
    <pubDate>Tue, 12 May 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42141</strong></p>
  <p>Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be exploited to scan internal…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41096 – Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41096</guid>
    <pubDate>Tue, 12 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41096</strong></p>
  <p>Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41089 – Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41089</guid>
    <pubDate>Tue, 12 May 2026 18:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41089</strong></p>
  <p>Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41088 – Access of resource using incompatible type ('type confusion') in Windows Ancilla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41088</guid>
    <pubDate>Tue, 12 May 2026 18:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41088</strong></p>
  <p>Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41086 – Improper access control in Windows Admin Center allows an authorized attacker to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41086</guid>
    <pubDate>Tue, 12 May 2026 18:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41086</strong></p>
  <p>Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40415 – Use after free in Windows TCP/IP allows an unauthorized attacker to execute code...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40415</guid>
    <pubDate>Tue, 12 May 2026 18:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40415</strong></p>
  <p>Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40414 – Windows TCP/IP Denial of Service Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40414</guid>
    <pubDate>Tue, 12 May 2026 18:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40414</strong></p>
  <p>Windows TCP/IP Denial of Service Vulnerability</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40413 – Windows TCP/IP Denial of Service Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40413</guid>
    <pubDate>Tue, 12 May 2026 18:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40413</strong></p>
  <p>Windows TCP/IP Denial of Service Vulnerability</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40410 – Use after free in Windows SMB Client allows an authorized attacker to elevate pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40410</guid>
    <pubDate>Tue, 12 May 2026 18:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40410</strong></p>
  <p>Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40408 – Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40408</guid>
    <pubDate>Tue, 12 May 2026 18:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40408</strong></p>
  <p>Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40407 – Heap-based buffer overflow in Windows Common Log File System Driver allows an au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40407</guid>
    <pubDate>Tue, 12 May 2026 18:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40407</strong></p>
  <p>Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40406 – Use after free in Windows TCP/IP allows an unauthorized attacker to disclose inf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40406</guid>
    <pubDate>Tue, 12 May 2026 18:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40406</strong></p>
  <p>Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40405 – Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40405</guid>
    <pubDate>Tue, 12 May 2026 18:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40405</strong></p>
  <p>Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40403 – Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40403</guid>
    <pubDate>Tue, 12 May 2026 18:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40403</strong></p>
  <p>Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40402 – Use after free in Windows Hyper-V allows an unauthorized attacker to elevate pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40402</guid>
    <pubDate>Tue, 12 May 2026 18:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40402</strong></p>
  <p>Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40401 – Windows TCP/IP Denial of Service Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40401</guid>
    <pubDate>Tue, 12 May 2026 18:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40401</strong></p>
  <p>Windows TCP/IP Denial of Service Vulnerability</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40399 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40399</guid>
    <pubDate>Tue, 12 May 2026 18:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40399</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40398 – Heap-based buffer overflow in Windows Remote Desktop allows an authorized attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40398</guid>
    <pubDate>Tue, 12 May 2026 18:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40398</strong></p>
  <p>Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40397 – Heap-based buffer overflow in Windows Common Log File System Driver allows an au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40397</guid>
    <pubDate>Tue, 12 May 2026 18:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40397</strong></p>
  <p>Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40382 – Use after free in Windows Telephony Service allows an authorized attacker to ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40382</guid>
    <pubDate>Tue, 12 May 2026 18:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40382</strong></p>
  <p>Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40377 – Heap-based buffer overflow in Windows Cryptographic Services allows an authorize...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40377</guid>
    <pubDate>Tue, 12 May 2026 18:17:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40377</strong></p>
  <p>Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40369 – Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40369</guid>
    <pubDate>Tue, 12 May 2026 18:17:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40369</strong></p>
  <p>Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35438 – Missing authorization in Windows Admin Center allows an authorized attacker to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35438</guid>
    <pubDate>Tue, 12 May 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35438</strong></p>
  <p>Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35424 – Missing release of memory after effective lifetime in Windows Internet Key Excha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35424</guid>
    <pubDate>Tue, 12 May 2026 18:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35424</strong></p>
  <p>Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35421 – Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35421</guid>
    <pubDate>Tue, 12 May 2026 18:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35421</strong></p>
  <p>Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35420 – Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35420</guid>
    <pubDate>Tue, 12 May 2026 18:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35420</strong></p>
  <p>Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35418 – Use after free in Windows Cloud Files Mini Filter Driver allows an authorized at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35418</guid>
    <pubDate>Tue, 12 May 2026 18:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35418</strong></p>
  <p>Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35417 – Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35417</guid>
    <pubDate>Tue, 12 May 2026 18:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35417</strong></p>
  <p>Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35416 – Access of resource using incompatible type ('type confusion') in Windows Ancilla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35416</guid>
    <pubDate>Tue, 12 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35416</strong></p>
  <p>Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35415 – Integer overflow or wraparound in Windows Storage Spaces Controller allows an au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35415</guid>
    <pubDate>Tue, 12 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35415</strong></p>
  <p>Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34351 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34351</guid>
    <pubDate>Tue, 12 May 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34351</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34347 – Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34347</guid>
    <pubDate>Tue, 12 May 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34347</strong></p>
  <p>Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34345 – Access of resource using incompatible type ('type confusion') in Windows Ancilla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34345</guid>
    <pubDate>Tue, 12 May 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34345</strong></p>
  <p>Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34344 – Access of resource using incompatible type ('type confusion') in Windows Ancilla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34344</guid>
    <pubDate>Tue, 12 May 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34344</strong></p>
  <p>Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34343 – Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34343</guid>
    <pubDate>Tue, 12 May 2026 18:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34343</strong></p>
  <p>Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34342 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34342</guid>
    <pubDate>Tue, 12 May 2026 18:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34342</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34342">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
