PatchSiren

Microsoft CVE debriefs · Page 38

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50486

CVE-2026-50486 is a high-severity vulnerability in Windows Runtime that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The vulnerability is a use-after-free issue in Windows Runtime, which could allow an attacker to [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50485

A buffer over-read vulnerability exists in Windows Hyper-V that could allow an authorized local attacker to cause a denial of service via an adjacent network. The vulnerability has a CVSS score of 4.5 and a severity rating of MEDIUM. Microsoft has released a patch for this vulnerability. This vulnerability affects Windows Hyper-V systems, and system administrators should review and update system configura [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50484

A high-severity vulnerability, CVE-2026-50484, exists in the Windows Kernel, allowing an authorized attacker to elevate privileges locally through a heap-based buffer overflow. This vulnerability has significant implications for Windows systems, particularly those with high-privilege access. The vulnerability's impact is amplified by its high CVSS score of 7.8 and its classification as HIGH severity. Affe [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50483

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:54.290Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-50483 is a medium-severity vulnerability in the Microsoft Graphics Component that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and a CVSS s [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50480

A heap-based buffer overflow vulnerability exists in the Windows Web Proxy Auto-Discovery Protocol (WPAD). An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This issue is particularly concerning because it allows for local privilege escalation, which can be used by an attacker to gain elevated [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50479

CVE-2026-50479 is a HIGH severity vulnerability in Windows USB Hub Driver. The vulnerability is caused by an untrusted pointer dereference, which allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.8. This vulnerability affects Windows systems and could allow an attacker with local access to gain elevated privileges. Administrators should be aware of thi [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50478

CVE-2026-50478 is a high-severity vulnerability in Windows Kernel, allowing an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. This use-after-free issue in the Windows Kernel requires careful review of system configurations and defensive strategies to prevent exploitation. System administrators and security teams must prioritize patch [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50477

A high-severity vulnerability, CVE-2026-50477, exists in the Windows Kernel, allowing an authorized attacker to elevate privileges locally through a heap-based buffer overflow. This vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. It affects various versions of Windows 10, Windows 11, and Windows Server. The vulnerability can be exploited by an authorized attacker to gain elevated [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50476

CVE-2026-50476 is a high-severity vulnerability in Microsoft Windows that allows an authorized attacker to elevate privileges locally. The vulnerability is caused by a use-after-free issue. This type of vulnerability can be particularly dangerous as it allows an attacker with existing access to the system to gain higher privileges, potentially leading to full system compromise. Administrators and users of [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50475

A buffer over-read vulnerability exists in the Windows Kernel, which could allow an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. This issue affects Windows systems, and administrators should be aware of its existence and take necessary precautions to mitigate its effects. The vulnerability is caused by a buffer over-read in the Wi [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50474

CVE-2026-50474 is a high-severity vulnerability in the Remote Desktop Client, allowing unauthorized attackers to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as CWE-416. Microsoft has released a patch for this vulnerability. Affected organizations should prioritize patching to prevent potential code execution attacks. The vulnerability's use-after-free issue in [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50473

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:52.857Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability in Windows File Explorer allows an authorized attacker to disclose sensitive information locally, with a CVSS score of 5.5 and a severity of MEDIUM. It affects various versions of Windows 1 [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50471

CVE-2026-50471 is a high-severity vulnerability in Windows NTFS that allows an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. This vulnerability affects multiple versions of Windows, including Windows 10, Windows 11, and Windows [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50470

CVE-2026-50470 is an out-of-bounds read vulnerability in Windows Network Policy Server SNMP. This vulnerability allows an unauthorized attacker to disclose information over a network. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. It affects various versions of Windows 10, Windows 11, and Windows Server. System administrators and security professionals should review the CVE and NVD entr [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50469

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:52.357Z and has not been modified since then. The NVD entry is currently Analyzed. This HIGH-severity vulnerability in Windows Projected File System allows an authorized attacker to elevate privileges locally through improper link resolution before file access. The vulnerability has a CVSS [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50468

A buffer over-read vulnerability exists in SQL Server 2025, which allows an authorized attacker to disclose information over a network. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. This issue arises from a buffer over-read in SQL Server, potentially exposing sensitive information. Security teams and administrators responsible for SQL Server 2025 should be aware of this vulnerability [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50467

AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-50467 is a high-severity Use after free vulnerability in Microsoft Office, allowing unauthorized attackers to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Affected products include Microsoft 365 Apps, Office 2016, Office 2019, Office 2021, and Office 2024 across various platforms. Org [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50466

CVE-2026-50466 is a high-severity vulnerability in Windows Brokering File System that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The vulnerability is a use-after-free issue in the Windows Brokering File System. [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50465

CVE-2026-50465 is a HIGH severity vulnerability in Microsoft Windows DNS, allowing an authorized attacker to perform tampering locally with a CVSS score of 7.1. The vulnerability is due to improper access control. Administrators and security teams responsible for Windows DNS servers should assess the vulnerability and apply patches or mitigations as necessary. The CVE record was published on 2026-07-14T18 [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50463

CVE-2026-50463 is an out-of-bounds read vulnerability in the Windows Kernel. This vulnerability allows an unauthorized attacker to disclose information over a network. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. System administrators and users should be aware of this vulnerability and take nece [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50462

CVE-2026-50462 is a HIGH severity vulnerability in Windows Ancillary Function Driver for WinSock, allowing an authorized attacker to elevate privileges locally. The vulnerability is caused by external control of file name or path, and Microsoft has released a patch for this vulnerability. System administrators and users of Windows operating systems should be aware of this vulnerability and apply the neces [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50461

A high-severity vulnerability, CVE-2026-50461, exists in Windows NTFS, allowing an unauthorized attacker to execute code locally through a heap-based buffer overflow. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability affects Windows operating systems and has not been modified since its publication on 2026-07-14T18:17:51.317Z. System administrators and users o [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50460

CVE-2026-50460 is a high-severity vulnerability in Windows Runtime that allows an unauthorized attacker to elevate privileges over a network. The vulnerability is caused by a race condition in Windows Runtime, which can be exploited by an attacker to gain elevated privileges. This vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. Users and administrators of these syste [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50459

CVE-2026-50459 is a high-severity vulnerability in the Windows Kernel that allows an unauthorized attacker to elevate privileges locally. The vulnerability is caused by a use-after-free issue. The affected products include Windows 10, Windows 11, and Windows Server systems. The vulnerability has a CVSS score of 7 and a CVSS severity of HIGH. Administrators and users should be aware of this vulnerability a [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50458

CVE-2026-50458 is a high-severity vulnerability in Microsoft Brokering File System, caused by a use-after-free issue. This allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.8, indicating a high level of severity. Affected products include Windows 11 24H2, 25H2, 26H1, and Windows Server 2025. Administrators and users of these systems should be aware of [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50457

CVE-2026-50457 is a high-severity vulnerability in Windows Runtime that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The vulnerability is a use-after-free issue in Windows Runtime that allows an authorized attacke [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50456

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:50.597Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability in Windows File Explorer allows an authorized attacker to disclose sensitive information locally, classified under CWE-200 with a CVSS score of 5.5 and a severity of MEDIUM. System administ [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50455

CVE-2026-50455 is a medium-severity vulnerability in the Universal Plug and Play (upnp) component. An authorized attacker can exploit this vulnerability locally to disclose information. The vulnerability has a CVSS score of 5.5. The upnp component is used for discovering and controlling network devices. This vulnerability could potentially allow attackers with local access to gain unauthorized information [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50454

A relative path traversal vulnerability exists in the Windows User Interface Core. An authorized attacker could exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. This vulnerability affects the Windows User Interface Core, allowing attackers with local access to potentially elevate their privileges. The vulnerability's high CVSS s [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50453

CVE-2026-50453 is an out-of-bounds read vulnerability in the Windows USB Audio Class driver (usbaudio.sys). An unauthorized attacker could exploit this vulnerability with a physical attack to disclose information. The vulnerability exists due to improper handling of audio data, allowing an attacker to read data out of bounds. This could potentially lead to information disclosure. System administrators and [truncated]