Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-21255
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-21238
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
CRITICAL 9.8
CVE-2026-24300
Azure Front Door Elevation of Privilege Vulnerability
Azure Front Door
No fix yet
CRITICAL 9.8
CVE-2026-24302
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Azure Arc
Mitigation only
CRITICAL 9.9
CVE-2026-24304
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Azure Resource Manager
Mitigation only
CRITICAL 9.8
CVE-2026-24306
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
Azure Front Door
No fix yet
HIGH 7.8
CVE-2026-20949
Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
365 Apps
No fix yet
HIGH 7.5
CVE-2026-20929
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.8
CVE-2026-20843
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 5.5
CVE-2026-20839
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.5
CVE-2026-0386
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
Windows Server 2008
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.8
CVE-2025-64669
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Windows Admin Center
2511+
HIGH 7.8
CVE-2025-64673
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8146 / 10.0.19044.6691+
MEDIUM 5.5
CVE-2025-62570
Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.
Windows 11 24h2
10.0.26100.7392 / 10.0.26200.7392+
HIGH 7.8
CVE-2025-62474
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8688 / 10.0.17763.8146+
HIGH 7.8
CVE-2025-59517
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8688 / 10.0.17763.8146+
HIGH 8.0
CVE-2025-64660
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
Visual Studio Code
1.106.2+
HIGH 7.8
CVE-2025-60705
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-59512
Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
MEDIUM 6.7
CVE-2025-47179
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.
Configuration Manager 2403
5.00.9128.1037 / 5.00.9132.1031+
HIGH 8.8
CVE-2025-59500
Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
Azure Notification Service
Mitigation only
CRITICAL 9.8
CVE-2025-59273
Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.
Azure Event Grid
No fix yet
HIGH 7.8
CVE-2025-59494
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Azure Monitor Agent
1.38.1+
MEDIUM 5.5
CVE-2025-59253
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-59230 KEV
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-59199
Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7919 / 10.0.19044.6456+
HIGH 7.8
CVE-2025-59201
Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.5
CVE-2025-58726
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-58724
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.57+
HIGH 7.8
CVE-2025-58714
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+