Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-26145
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Azure Synapse
No fix yet
CRITICAL 9.9
CVE-2026-47647
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
Dynamics 365
Mitigation only
HIGH 7.8
CVE-2026-49161
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
Pc Manager
3.21.6.0+
HIGH 7.9
CVE-2026-48578
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
MEDIUM 6.8
CVE-2026-45658
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.9
CVE-2026-45654
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Windows 11 24h2
10.0.26100.8655 / 10.0.26100.32995+
HIGH 7.1
CVE-2026-45649
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
Excel
No fix yet
HIGH 7.8
CVE-2026-42829
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.
Windows 11 24h2
10.0.26100.8655 / 10.0.26200.8655+
HIGH 7.8
CVE-2026-41092
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
CRITICAL 9.9
CVE-2026-42823
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Azure Logic Apps
Mitigation only
MEDIUM 5.5
CVE-2026-42832
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
Excel
16.0.19822.20190+
MEDIUM 6.2
CVE-2026-41614
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
365 Copilot
19.2604.43111.0+
MEDIUM 5.5
CVE-2026-41101
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
Word
16.0.19822.20190+
MEDIUM 5.5
CVE-2026-41102
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
Powerpoint
16.0.19822.20190+
HIGH 8.8
CVE-2026-40420
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
HIGH 8.8
CVE-2026-41086
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
2.6.7+
HIGH 7.8
CVE-2026-40381
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.63+
HIGH 7.8
CVE-2026-33834
Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
CRITICAL 10.0
CVE-2026-35435
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
CRITICAL 9.9
CVE-2026-33109
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Azure Managed Instance For Apache Cassandra
Mitigation only
CRITICAL 9.6
CVE-2026-24303
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
Partner Center
No fix yet
MEDIUM 5.5
CVE-2026-33103
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
Dynamics 365
9.1.44.15+
MEDIUM 5.5
CVE-2026-32214
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
HIGH 7.8
CVE-2026-27914
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
HIGH 7.8
CVE-2026-26183
Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.
Windows Server 2012
10.0.14393.9060 / 10.0.17763.8644+
HIGH 7.8
CVE-2026-25176
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.8
CVE-2026-24290
Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8511 / 10.0.19044.7058+
HIGH 7.8
CVE-2026-23660
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
Windows Admin Center
2.6.4+
HIGH 8.8
CVE-2026-21262
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Sql Server 2016
13.0.6480.4 / 13.0.7075.5+
HIGH 7.5
CVE-2026-21535
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
Teams
Mitigation only