Autor: Peter Leibling

CVE-2026-26180 Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-32226 .NET Framework Denial of Service Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in .NET Framework allows an unauthorized attacker to deny service over a network.

CVE-2026-32631 GitHub: CVE-2026-32631 ‚git clone‘ from manipulated repositories can leak NTLM hashes

[CVE-2026-32631](https://www.cve.org/CVERecord?id=CVE-2026-32631) is regarding a vulnerability where it is possible to obtain a user’s NTLM hash by tricking them into cloning a malicious repository, or checking out a malicious branch that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. GitHub created this CVE on their behalf. The documented Visual Studio…
Weiterlesen

CVE-2026-32218 Windows Kernel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-26181 Microsoft Brokering File System Elevation of Privilege Vulnerability

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-32212 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability

Improper link resolution before file access (‚link following‘) in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

CVE-2026-27906 Windows Hello Security Feature Bypass Vulnerability

Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

CVE-2026-26175 Windows Boot Manager Security Feature Bypass Vulnerability

Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-26183 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability

Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.

CVE-2026-33826 Windows Active Directory Remote Code Execution Vulnerability

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.