Autor: Peter Leibling

CVE-2026-23666 .NET Framework Denial of Service Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in .NET Framework allows an unauthorized attacker to deny service over a network.

CVE-2026-27915 Windows UPnP Device Host Elevation of Privilege Vulnerability

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

CVE-2026-27908 Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability

Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-27917 Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability

Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-26152 Microsoft Cryptographic Services Elevation of Privilege Vulnerability

Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

CVE-2026-23657 Microsoft Word Remote Code Execution Vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-27906 Windows Hello Security Feature Bypass Vulnerability

Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

CVE-2026-33826 Windows Active Directory Remote Code Execution Vulnerability

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

CVE-2026-33825 Microsoft Defender Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVE-2026-26175 Windows Boot Manager Security Feature Bypass Vulnerability

Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.