CVE-2026-20849 Windows Kerberos Elevation of Privilege Vulnerability

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.


Chromium: CVE-2026-0908 Use after free in ANGLE

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.


Chromium: CVE-2026-0907 Incorrect security UI in Split View

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.


Chromium: CVE-2026-0905 Insufficient policy enforcement in Network

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.


CVE-2026-20958 Microsoft SharePoint Information Disclosure Vulnerability

Updated acknowledgment. This is an informational change only.


CVE-2025-64679 Windows DWM Core Library Elevation of Privilege Vulnerability

Updated the build numbers. This is an informational update only.


CVE-2026-20941 Host Process for Windows Tasks Elevation of Privilege Vulnerability

Improper link resolution before file access (‘link following’) in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.


CVE-2026-20805 Desktop Window Manager Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.


CVE-2026-20965 Windows Admin Center Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.


CVE-2026-20803 Microsoft SQL Server Elevation of Privilege Vulnerability

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

AbuseIPDB Contributor Badge