CVE-2026-20848 Windows SMB Server Elevation of Privilege Vulnerability

Updated the build numbers. This is an informational update only.


CVE-2026-21221 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

Updated the build numbers. This is an informational update only.


CVE-2026-20830 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

Updated the build numbers. This is an informational update only.


CVE-2026-20943 Microsoft Office Click-To-Run Remote Code Execution Vulnerability

Updated FAQ information. This is an informational change only.


CVE-2026-20818 Windows Kernel Information Disclosure Vulnerability

Updated the build numbers. This is an informational update only.


Chromium: CVE-2026-0899 Out of bounds memory access in V8

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.


CVE-2026-21223 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected […]


CVE-2026-20960 Microsoft Power Apps Remote Code Execution Vulnerability

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.


CVE-2026-20929 Windows HTTP.sys Elevation of Privilege Vulnerability

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.


CVE-2026-20867 Windows Management Services Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Management Services allows an authorized attacker to elevate privileges locally.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

AbuseIPDB Contributor Badge