Autor: Peter Leibling

CVE-2026-23656 Windows App Installer Spoofing Vulnerability

Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-24289 Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-25189 Windows DWM Core Library Elevation of Privilege Vulnerability

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-25174 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.

CVE-2026-23667 Broadcast DVR Elevation of Privilege Vulnerability

Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.

CVE-2026-26141 Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

CVE-2026-25176 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-26118 Azure MCP Server Tools Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-24283 Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.

CVE-2026-26108 Microsoft Excel Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.