Windows Server (General) · Top 20

Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2026-20810 CVSS 7.8 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

Microsoft CVE-2026-20825 CVSS 4.4 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2026-20831 CVSS 7.8 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.

Microsoft CVE-2026-20833 CVSS 5.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Microsoft CVE-2026-20840 CVSS 7.8 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2026-20843 CVSS 7.8 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Microsoft CVE-2026-20848 CVSS 7.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Microsoft CVE-2026-20849 CVSS 7.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

Microsoft CVE-2026-20854 CVSS 7.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Microsoft CVE-2026-20856 CVSS 8.1 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2026-20860 CVSS 7.8 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Microsoft CVE-2026-20868 CVSS 8.8 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Microsoft CVE-2026-20875 CVSS 7.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Microsoft CVE-2026-20919 CVSS 7.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Microsoft CVE-2026-20921 CVSS 7.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Microsoft CVE-2026-20922 CVSS 7.8 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Microsoft CVE-2026-20926 CVSS 7.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.

Microsoft CVE-2026-20927 CVSS 5.3 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

Microsoft CVE-2026-20929 CVSS 7.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Microsoft CVE-2026-20934 CVSS 7.5 2026-01-13 08:00 UTC · 2026-01-13 05:00 -03