Autor: Peter Leibling

CVE-2026-23664 Azure IoT Explorer Information Disclosure Vulnerability

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVE-2026-26127 .NET Denial of Service Vulnerability

Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.

CVE-2026-25180 Windows Graphics Component Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

CVE-2026-23667 Broadcast DVR Elevation of Privilege Vulnerability

Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.

CVE-2026-23668 Windows Graphics Component Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2026-26141 Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

CVE-2026-26114 Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-25176 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-26108 Microsoft Excel Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-24282 Push message Routing Service Elevation of Privilege Vulnerability

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.